By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Hackers are impersonating banks to infect your Android phone with credit card-stealing malware
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Hackers are impersonating banks to infect your Android phone with credit card-stealing malware
News

Hackers are impersonating banks to infect your Android phone with credit card-stealing malware

News Room
Last updated: 2025/04/21 at 4:56 PM
News Room Published 21 April 2025
Share
SHARE

Hackers love using malware to go after your credit card details but a new malware-as-a-service platform makes it incredibly easy for them to use these stolen cards in person at stores and even at ATMs.

As reported by BleepingComputer, SuperCard X is the platform in question and it’s currently being used to target the best Android phones via NFC relay attacks. With your credit card details in hand, the hackers behind this campaign then use them to make small transactions and withdrawals at ATMs to avoid having them flagged as fraudulent.

Discovered by the mobile security firm Cleafy, SuperCardX bears a lot of similarities to the NGate malware I covered last summer. It too uses contactless cards to commit fraud by taking over a vulnerable device’s NFC capabilities.


You may like

Here’s everything you need to know about this new Android malware threat, how to avoid falling victim to it and some tips and tricks to keep your phone malware-free and safe from hackers.

From phishing to social engineering to fraud

Just like with other malware attacks, this one begins with a victim receiving a text message or a WhatsApp message impersonating their bank. This phishing message claims that they need to call a number to resolve issues with their account caused by a suspicious transaction.

The hackers behind this campaign pose as bank support on the other end of the call and they use social engineering to trick potential victims into “confirming” their card number and PIN. From there, they then try to convince the victim to remove spending limits via their banking app which is definitely a red flag as no bank would try to do something like this over the phone.

To gain access to their credit cards, the hackers convince victims to install a malicious app called Reader that’s disguised as either a security or verification tool. As you may have guessed, it contains the SuperCard X malware.

Get instant access to breaking news, the hottest reviews, great deals and helpful tips.

(Image credit: Cleafy / Tom’s Guide)

After installation, the Reader app doesn’t request loads of unnecessary permissions like we’ve seen other malicious apps do in the past. Instead, it only asks for a few essential permissions with the main one being access to an Android device’s NFC module.

The app then tells victims to tap their payment cards to their phone and to verify them. This allows the malware to read a card’s chip data and send it back to the hackers behind this campaign. This data arrives on a hacker-controlled phone which runs another app called Tapper which is able to emulate a victim’s card using this stolen data.

The hackers then use these emulated cards to make contactless payments at stores and to withdraw small amounts of money from ATMs. Since all of these transactions are small and happen instantly, a victim’s bank likely won’t even flag them as fraudulent and reverse the charges.

How to stay safe from Android malware

Android malware on phone

(Image credit: Shutterstock)

The good news with this campaign is that according to Cleafy’s report, SuperCard X is currently only being used by hackers and scammers in Italy. However, since it is a malware-as-a-service offering purchased on the dark web, it could easily spread to other countries and continents any day now. As such, here are a few tips and tricks to stay safe from SuperCard X and other Android malware.

In this particular campaign, a random text from your bank is the kind of lure that you should know to avoid but can still fool some people due to the sense of urgency used in the message. Instead of responding to the message, you can always try looking up the phone number first. However, if the hackers or scammers spoofed your bank quite well, that number will be the same. In that case, it’s always a good idea to call your bank directly to verify something like this before responding.

Another big warning sign is when the hackers behind this campaign sent potential victims a URL for an app to download to their phone. No legitimate bank would ever ask you to do something like this and instead, they’d point you to their app’s listing page on the Google Play Store.

As for staying safe from Android malware, you want to make sure that Google Play Protect is enabled on your devices. This free, built-in security app checks all of the new apps you download as well as the existing ones on your phone or tablet for malware. For additional protection though, you might want to consider running one of the best Android antivirus apps alongside it.

Now that SuperCard X is being used in attacks in the wild, I wouldn’t be surprised if other hackers and scammers started using this new malware-as-a-service in attacks in the U.S. and other countries.

By practicing good cyber hygiene and staying up to date on the latest threats (by reading this and other security articles on Tom’s Guide), you’ll be prepared to recognize the warning signs before it’s too late.

More from Tom’s Guide

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Game Boy clone maker Anbernic suspends all shipments to US
Next Article Trump wants to kill one of the biggest space missions of our lifetime
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Should Apple Do a Big Deal to Catch Up on AI?
Software
65% of Freight Pros See Self-Driving Trucks on US Roads by 2050
News
Top TikToker Khaby Lame detained by US immigration
News
Why your refunds take forever and how Recital is fixing It
Computing

You Might also Like

News

65% of Freight Pros See Self-Driving Trucks on US Roads by 2050

2 Min Read

Top TikToker Khaby Lame detained by US immigration

3 Min Read

Musk could lose billions of dollars depending on how spat with Trump unfolds

8 Min Read
News

The impossible is happening: An Android phone will be compatible with Apple Watch

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?