SuperCard X

SuperCard X: An Emerging Threat for Android Users

The New Android Malware That Uses NFC Relay Attacks to Steal Your Money

A new malware-as-a-service (MaaS) platform, named “SuperCard X”, has surfaced, targeting Android devices through Near-Field Communication (NFC) relay attacks; this is where criminals intercept and relay NFC signals between two devices to conduct fraudulent transactions. SuperCard X enables unauthorised point-of-sale and ATM transactions using stolen payment card data, posing a significant risk to unsuspecting users.

Linked to Chinese-speaking threat actors, SuperCard X shares similarities with NFCGate and its malicious variant, NGate, which have been active in Europe.

How Does It Work?

The attack process begins with victims receiving deceptive messages via text or WhatsApp, often impersonating their bank, urging them to call a number to resolve issues caused by a suspicious transaction. The call is then answered by a scammer who uses social engineering tactics to “confirm” the victim’s card details and PINs, and tries to convince the victim to remove any spending caps on their bank account via their banking app. The scammer then tells the victim to install a malicious app disguised as a security or verification tool and asks them to tap their payment card to their phone to verify their cards, which sends a replica of their chip data to the attacker. The stolen information is then used to emulate the victim’s card for contactless payments and ATM withdrawals via NFC.

SuperCard X

SuperCard X employs advanced techniques to evade detection, including minimal permission requests and ATR-based card emulation, which makes transactions appear legitimate. Additionally, its use of Mutual Transport Layer Security (mTLS: an advanced cryptographic protocol that secures data transmission over networks, where both the client and server authenticate each other using digital certificates before establishing a connection) ensures secure communication between the malware and its command-and-control servers, complicating efforts to intercept or analyse its activities.

How Can You Protect Yourself?

Like many cyber threats, the number 1 failure in protecting data is human error. To keep yourself safe from SuperCard X and other emerging threats, you must be vigilant and refuse to give any sensitive information or complete any tasks without confirming through a valid source it is completely legitimate.

In addition to your own precautions, you can also install powerful endpoint security such as WatchGuard Endpoint Security to scan for malicious activity on your mobile or other devices.

If you’d like to find out more about protecting yourself or your business from emerging cyber threats, get in touch with our experienced Cyber Security Department here at Logic Business Systems, Carlisle.

Blog Top Picks

Rockstar Games Was Hacked by Teenagers

The GTA 6 trailer has been released! But aren’t we forgetting something? An 18-year-old and 17-year-old were responsible for the GTA 6 footage leak in 2022. If Rockstar Games can be targeted by teenage cyber criminals, then so can your business.

Read More »
Facebook
Twitter
LinkedIn

Terms of Use   /   Privacy Policy        Company Registration Number: 02059640