In brief

A primer on NFC fraud: NFCGate (for the speaker, the same thing as NGate) and its derivatives relay card data so that cash can be withdrawn from ATMs. There is little forensics here — one case belonging to someone else, picked up at a seminar (Redmi Note 11S, the vtb1 trojan, 230 thousand rubles), "we didn't do that examination ourselves". What is valuable for experts are the artifacts: the Telegram directory, cache4.db, the APK manifest, the logs of the app being uninstalled and of the NFC service starting.

Key points

  1. In 2025 there were 35 times more NFC crimes than in the second half of 2024 — new malware and relaying. NGate/NFCGate sends card data through compromised smartphones to an ATM; GhostTap ("Chinese developers") uses phishing to link 4–6 sets of payment card details to a device, and those are sold on Telegram "for hundreds of dollars"; SuperCard X (also "Chinese people") covertly collects card data. The channels with instructions have thousands of members; the groups are split by region: the United States/the UK/Australia/Canada, Malaysia/Japan/Taiwan, Africa.
  2. Russia: the first reports came in August 2024, ~40 million rubles stolen, a forecast of 30–35% growth a month; in 2025 ~400 crimes, mostly NFCGate/NGate, with an average amount of ~100 thousand rubles.
  3. The classic scheme: the victim is convinced to install a "specially secured" application, to hold their card up and to enter the PIN — the data goes to the suspect standing at an ATM. The reverse one: malware relays the suspect's card, and the victim is guided into depositing money into a "safe account".
  4. NFCGate is legitimate interception and analysis of NFC traffic, a student project at a university in Darmstadt, with the code on GitHub. Clone — a copy of the tag, a rooted device is required; Relay — the signal travels over the network from the reader to the tag "anywhere in the world at all", the limiting factor being the contactless payment limit of 3,000 rubles, on some terminals 1,000 rubles; Capture — passive collection; Replay — traffic recorded once emulates the card "an unlimited number of times".
  5. More than 100 unique NFCGate derivatives disguise themselves as apps of government agencies and banks; the scheme "caught off guard" their security staff.
  6. The attack: social engineering (renewing a mobile contract, "hacked Gosuslugi", bank card protection, a health insurance policy) → an APK via a messenger, installation by a RAT trojan → NFCGate in Relay Mode with its own server; the suspect is the Tag, the victim is the reader, readiness is signaled by the green Network Connect to Partner. The PIN is obtained by social engineering, by a keylogger through the RAT or by a pop-up window; the modifications are given away by the UI, the hiding of push notifications, the changing of package names and of the data format.
  7. The case: a call on Telegram from "a law enforcement officer", the app installed, instructions given, advice to delete it; 230 thousand rubles withdrawn. A Redmi Note 11S, an advanced file system extraction with Mobile Criminalist Expert Plus, the MTK Android method.
  8. Artifacts: vtb1 in the Telegram directory, created/modified on 22.01.25 at 10:20; the sender — "7…", the file — "52, then 93"; in cache4.db the receipt on 22.01.25 at 10:20:44 matches. The manifest: Darmstadt, the AppName "VTB Protection", the server IP (hidden); uninstalled twice on 23.01.25 at 11:16 and 11:41; the start of the NFC service is logged; in the banking directory — a file recording a withdrawal of the same amount.
  9. Preventing "carding": official stores only, do not share card details, check by calling the hotline, block the card quickly.

Tools, artifacts, technologies

No articles of law, laws, methodologies or regulators were mentioned. The terminology — "a real criminal investigation", "trace picture", "carding"; from the audience — "we try to go down the same route through the EKC". The background — contactless payment limits and the security services of banks.

Questions from the audience

The speaker's position

A primer-style lecture with jokes ("We've got gas in our flat, as the rhyme goes", the trojan as a "little beast") and a closing line from "The Twelve Chairs"; the message is protective: the experts are the "anchor" for ordinary citizens. He stresses the "Chinese", inviting the audience to "draw your own conclusions". He admits the limits honestly, but mostly only under questioning.

Quotes