Sunday, September 13, 2026

SuperCard Malware Hijacks Android Devices to Steal Payment Card Data and Relay it to Attackers

F6, a leading developer of technologies to combat cybercrime, has reported the emergence of SuperCard, a malicious modification of the legitimate NFCGate program, now targeting Android users globally, with recent attacks recorded in Russia.

Initially detected in Europe during spring 2025, where it struck clients of European banks, this malware surfaced in Russia by May 2025, as per F6’s Fraud Protection department.

SuperCard exploits Near Field Communication (NFC) traffic to intercept sensitive bank card data, enabling attackers to siphon funds directly from victims’ accounts.

This rapid spread within a month from its European debut to Russian attempts highlights the aggressive adaptability of cybercriminals, who appear to be testing this new strain in diverse regions without geographical restrictions.

Technical Disparities

The SuperCard malware, distributed via a Malware-as-a-Service (MaaS) platform named SuperCard X, was first flagged by Italian cybersecurity firm Cleafy in April 2025.

Unlike earlier malicious versions of NFCGate sold on the darknet, SuperCard is uniquely marketed through Telegram channels with customer support, primarily in Chinese and English, targeting users of major banks in the US, Australia, and Europe.

According to the Report, F6’s Threat Intelligence Department uncovered these channels, noting the malware’s subscription-based model and multilingual support.

Technical analysis by F6 revealed significant differences in functionality and code structure among SuperCard samples, suggesting development by multiple attacker groups.

This fragmentation indicates a dynamic ecosystem of cybercrime where tools are continuously refined.

The impact in Russia alone is staggering, with damages from NFCGate variants reaching 432 million rubles in Q1 2025, affecting over 175,000 Android devices.

As Dmitry Ermakov, head of F6’s Fraud Protection, warns, the rapid evolution of these threats evidenced by weekly new modifications poses a steep challenge, with attackers borrowing successful tactics from global campaigns to target Russian bank clients.

Protective Measures Against SuperCard Exploits

To counter SuperCard, F6 urges users to exercise caution by avoiding interactions with unknown contacts, refraining from clicking suspicious links, and installing apps only from trusted stores like Google Play or RuStore after checking reviews.

Users should also scrutinize app permissions for NFC access and default payment settings, deleting any unfamiliar or unsolicited applications.

For banks, F6 recommends bolstering anti-fraud systems with behavioral analytics, cross-channel session data, and real-time transaction risk assessment using solutions like F6 Fraud Protection.

Additional measures include verifying user geolocation and requesting physical cards during suspicious NFC transactions at ATMs.

As SuperCard continues to evolve, blending social engineering with advanced technical exploits, both individual vigilance and institutional defenses remain critical to mitigating this escalating cyber threat.

Find this News Interesting! Follow us on Google News, LinkedIn, and X to Get Instant Updates

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News