NFCShare fake banking-app update phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The NFCShare phishing campaign is using fake banking-app updates on GitHub to steal payment card data from customers of multiple banks across Europe, expanding the theft risk across a broad financial-services target set. The operation combines impersonated bank login pages, deceptive update prompts, and malicious Android packages to capture card details and a 4-digit PIN. It matters because the theft path is built for reusable fraud against bank customers rather than a single isolated lure.
Related Happenings
Ousaban banking trojan retooled for Spain and Portugal
Malware Activity
H score33
First: 01.07.2026 16:45
Last: 01.07.2026 16:45
Sources 1
About this happening:
The Ousaban banking trojan has been retooled to target banking customers in Spain and Portugal, raising the risk of credential theft and bank fraud. It uses ...
Ousaban banking trojan retooled for Spain and Portugal
Malware ActivityAbout this happening: The Ousaban banking trojan has been retooled to target banking customers in Spain and Portugal, raising the risk of credential theft and bank fraud. It uses ...
Rust-based clipboard hijacker that swaps wallet addresses
Malware Activity
H score10
First: 17.06.2026 21:14
Last: 17.06.2026 21:14
Sources 1
About this happening:
The Rust-based clipper is a Windows and macOS malware activity that replaces copied cryptocurrency wallet addresses with attacker-controlled destinations. It continuou...
Rust-based clipboard hijacker that swaps wallet addresses
Malware ActivityAbout this happening: The Rust-based clipper is a Windows and macOS malware activity that replaces copied cryptocurrency wallet addresses with attacker-controlled destinations. It continuou...
Ghost Networks crypto-clipper promotion campaign
Campaign
H score15
First: 17.06.2026 21:14
Last: 17.06.2026 21:14
Sources 1
About this happening:
Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...
Ghost Networks crypto-clipper promotion campaign
CampaignAbout this happening: Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...
GitBait phishing campaign targeting Mexican banks
Campaign
H score20
First: 17.06.2026 17:00
Last: 17.06.2026 17:00
Sources 1
About this happening:
A long-running GitBait phishing campaign is stealing banking credentials from customers of Mexican financial institutions, using GitHub Pages and SheetBest to...
GitBait phishing campaign targeting Mexican banks
CampaignAbout this happening: A long-running GitBait phishing campaign is stealing banking credentials from customers of Mexican financial institutions, using GitHub Pages and SheetBest to...
Rokarolla Android banking trojan activity
Malware Activity
H score26
First: 16.06.2026 16:15
Last: 16.06.2026 16:15
Sources 1
About this happening:
The Rokarolla Android banking trojan is expanding phone-level control on infected devices, letting attackers steal credentials, intercept authentication codes, and hide fr...
Rokarolla Android banking trojan activity
Malware ActivityAbout this happening: The Rokarolla Android banking trojan is expanding phone-level control on infected devices, letting attackers steal credentials, intercept authentication codes, and hide fr...
Timeline
-
09.06.2026 01:11 1 articles · 1mo ago
GitHub repository starts hosting NFCShare banking-app APKs
Campaign Scope UpdateA GitHub repository used for NFCShare distribution is created on April 10 and goes on to host 56 unique APKs that impersonate mobile banking apps, primarily for banks in Italy and Spain, widening the malware distribution infrastructure.
Show sources
- NFCShare Android malware spreads via fake banking app updates on GitHub — www.bleepingcomputer.com — 09.06.2026 01:11
-
09.06.2026 01:11 1 articles · 1mo ago
Phishing sites push bank customers to NFCShare malicious APKs
Exploitation ObservedBeginning May 14, victims across Europe visit phishing sites that impersonate real banks, are prompted to update a banking app, and are redirected to a GitHub repository hosting a malicious APK; after a fake verification screen asks them to place a card near the device NFC chip, NFCShare reads the card using Android’s IsoDep interface and EMV commands.
Show sources
- NFCShare Android malware spreads via fake banking app updates on GitHub — www.bleepingcomputer.com — 09.06.2026 01:11
-
09.06.2026 01:11 2 articles · 1mo ago
Researchers report NFCShare variants targeting bank customers across Europe
Technical Analysis UpdateD3Lab, which first documented NFCShare in January 2026, reports new variants of the Android malware being distributed as fake updates for legitimate banking apps hosted on GitHub, targeting customers of multiple banks and financial institutions across Europe; the newer samples add malformed APK packaging to hinder automated analysis, while the malware steals the card number, type, expiry date, and a 4-digit PIN before exfiltrating them to a C2 host over WebSocket.
Show sources
- NFCShare Android malware spreads via fake banking app updates on GitHub — www.bleepingcomputer.com — 09.06.2026 01:11
- NFCShare Android malware spreads via fake banking app updates on GitHub — www.bleepingcomputer.com — 09.06.2026 01:11