# Applying forensic methods to investigate thefts committed with NFC technology Alexey Moskvichev · MKO Systems MOSCOW FORENSICS DAY ’25 · Day 1 — Thursday, 11 September 2025: digital forensics day · Scheduled 13:05–13:35 · In the recording 01:40:39–02:18:13 Talk transcript · https://2025.moscow-forensics-day.workers.dev/en/transcript/05-moskvichev Summary: https://2025.moscow-forensics-day.workers.dev/en/summary/05-moskvichev · Slides: https://2025.moscow-forensics-day.workers.dev/en/slides/05-moskvichev-forenzika-nfc · Watch from 01:40:39: https://youtu.be/4V7Wez3L_58?t=6039 --- ## Moderator's introduction So, friends, by and large we're moving on. And before we move on to the next topic, let's chat a little. Surely, it seems to me, everyone has some favorite sound. Well, I like the "ding" when, for example, my salary comes in. But then again, that "ding" may not always be a good thing, because the "ding" when the salary comes in — that's good, that's happiness, joy, dopamine. But sometimes you also get that "ding", and money is debited, and unfortunately it's not being debited to you. It's exactly such cases my colleague Alexey Moskvichev will talk about, and how they're investigated. Please welcome him with applause. Alexey, the microphones, everything is yours. ## Talk and Q&A Can you hear me? Yes. Dmitry, thank you very much. Let me start by introducing myself: at the company, I'm in charge of training. Apart from that, my colleagues and I regularly travel to the regions, we run a series of seminars. And at one of those seminars, some information was shared with us by our wonderful user, who I hope is watching us, he couldn't make it here, unfortunately. That information became the basis of my talk today. Well, before I get to the substance of the announced topic, let's briefly talk about what NFC actually is and go over its key features. So, NFC is a short-range wireless communication technology that uses radio-frequency identification to recognize objects and devices and to read information. Basically, it has become a firm part of our everyday life and is widely used in mobile wallets, access control systems, for example, access to office premises, and in most self-service systems. And here in front of you are some of its key features. First, it's short-range communication, that is, NFC's range is 3 to 4 centimeters, which, on one hand, ensures its security, and the connection's precision. Next is fast pairing, that is, it's enough to simply hold two devices up to each other for a connection to be established. The next feature is low power consumption, that is, NFC consumes very little energy, which makes it convenient for small devices that in some cases need a long standby period. Basically, it's supported by most general-purpose applications, as I've already said: mobile banking, personal identification, transferring data, photos, contacts, paying for public transport fares, and much, much more. But who would have thought that, on the one hand, this seemingly convenient and supposedly secure technology would become a serious weapon in the hands of criminals, one capable of draining the personal accounts of people all over the world. And here's a bit of statistics, global for now. In 2025, the number of crimes committed using NFC technology grew 35-fold compared to the second half of 2024. Just think about that figure. Of course, this was helped along by the emergence of all sorts of malware and new relay schemes. And in particular, listed here in front of you are several such applications, using one as an example, we'll go through a practical case from a real criminal investigation. The first is the NGate, or NFCGate, application, which transmits NFC data from payment cards via compromised smartphones, for subsequently carrying out fraudulent cash withdrawals at ATMs. The next application, GhostTap — behind it are, by the way, Chinese developers — steals card data, and loads it into digital wallets for making contactless payments. Basically, phishing is used first, and then the payment card details of the victim are linked to the suspect's device. And one such device can have from 4 to 6 sets of card details linked to it. Later, on the secondary market, such devices are sold via various Telegram channels, even for hundreds of dollars. A similar application, SuperCard X, also, by the way, has Chinese people behind it. I've said "Chinese" twice now, draw your own conclusions. Likewise, on the one hand, it presents itself as a supposedly safe application, but on the other, it actually covertly collects bank card data and transmits it for conducting quick illegal transactions. And a huge number of Telegram channels are springing up like mushrooms, publishing detailed instructions, training videos that even untrained users can understand. In particular, while preparing for this talk, we looked through some of those Telegram channels. Some of them, by the way, have thousands of members. And what's also notable is that from the context of the chats it became clear that some of the groups that use these fraud schemes are targeting, for example, the United States, the UK, Australia, Canada, others target Malaysia, Japan, Taiwan, and still others, African countries. That is, as you can see, there's a certain division along regional lines. And let's keep Telegram in mind here, because we'll be coming back to it. What about Russia? What about us? We've got gas in our flat, as the rhyme goes. In Russia, the first reports of crimes committed using NFC technology appeared in August 2024. Back then, the amount stolen was around 40 million rubles. And, well, analysts predicted such crimes would grow by around 30-35% a month. And basically, that's what happened. In 2025, around 400 such crimes had already been recorded, committed mostly using the application NFCGate, or NGate, and derivatives of that application. And the average amount stolen was around 100 thousand rubles. And, basically, two criminal schemes were used. Let's briefly go over them too. The first is the classic scheme. The victim's phone receives a call. The fraudster convinces them to install some kind of "specially secured" application on the victim's device, after which the victim is asked, following instructions over the phone, to hold their bank card up to the NFC sensor of their smartphone, to enter the PIN; they insist it's safe to enter the details, the card itself stays with you, the PIN isn't dangerous, but in fact this very application collects the NFC data of the victim's bank card and sends it over to the suspect, who at that moment may be standing at a payment terminal, at an ATM, and holds up their own identical device with the app installed. So there are already two devices here. NFCGate on the victim's side and the same application on the suspect's side. And basically the money gets cashed out. The essence of the reverse scheme is that some kind of malware is installed on the victim's phone, which relays the signal from the suspect's card to the victim's device. So in fact the sequence of actions is different here. The victim is guided over the phone to an ATM and asked to deposit money into a supposedly "safe account", but it ends up on the suspect's card. So those are usually the two schemes. Let's go through how NFCGate, or NGate, works. In general, it's a legitimate application for capturing, monitoring and analyzing NFC traffic by intercepting and replaying it. It was actually developed as a student project at one of Germany's technical universities, in Darmstadt. The source code is on GitHub; by the way, you can have a look at it, if you're interested. See, there's a QR code here on the right, you can go and study it in general, if you're interested. And in fact this application has several operating modes, each of which handles this NFC traffic in its own way and basically works with it differently. Here's the first mode, Clone Mode. It reads a tag and instantly replays its signal, but here, to replay this NFC signal, a rooted device is required, that is, a device with superuser rights, in order to replay this NFC signal. For example, when could this be useful. Say I need an access card, either to an office or to a warehouse. Somewhere at the reception desk or, say, in the parking lot next to the office, I try to read, using a device like this with NFCGate installed, some employee's card. Then I make an exact copy, and basically I can walk into the premises unhindered. That's the essence of this mode. The next mode, Relay Mode, lets you transmit this NFC signal over the network. That is, in this scheme, several devices with NFCGate installed are used. That is, one device acts as the reader, meaning it reads the tag. And the second device acts as that very tag, replaying the signal. Here's an example. Somewhere on public transport. I have a reader like this with NFCGate. I try to read the victim's cards. At that moment the card may be in a pocket, in a handbag, doesn't matter. Meanwhile my colleague, my accomplice, is anywhere in the world at all, and picks up this signal using his device, which acts as that very tag. And then he can make, for example, contactless payments. But again, there are nuances here. For example, in Russia there are limits on contactless payments. Most POS terminals support them, and on most POS terminals that limit is 3,000 rubles, on some it's 1,000 rubles. So you probably won't get rich, but probably enough for gum and a Coca-Cola. Here you'd probably have to go for volume. The next mode, Capture Mode, is mostly, I suppose, geared towards penetration testing. A pentest, right? That is, passively collecting this traffic to see whether or not the NFC signal can be replayed. That is, looking for vulnerabilities and possible ways to break in. This mode is geared mostly towards that. And finally, the last mode, Replay Mode. We've already said that NFCGate is an application for intercepting and replaying NFC signals. So in this mode, you can emulate a bank card over and over again. That is, having recorded once, recorded this NFC traffic of one of the devices that were communicating, you can emulate it repeatedly, that is, emulate the bank card an unlimited number of times. That's the essence of this mode. So, since NFCGate first started being used in attacks on bank customers, this app has seen a number of modifications. And in fact the fraudsters themselves have learned to disguise these applications as popular government or banking apps. And in fact this new fraud scheme caught the security staff of credit institutions off guard, and what was found was more than 100 unique applications, or derivatives based on NFCGate, which, basically, handled NFC data in different ways. So let's go through how attacks using NFCGate work, as an algorithm, in its pure form. What, in fact, does it start with. The first stage is most often based on plain social engineering, that is, the victim, under some pretext, renewing a mobile contract, hacked Gosuslugi, bank card protection, renewing a health insurance policy, it varies, all sorts of variations are possible here, is asked to install this certain application on their device. And this application looks similar to a legitimate app, either of a government agency or a bank, but in fact it's precisely NFCGate, which most often runs in Relay Mode. As for remote installation of this application, so they've supposedly convinced them over the phone, and contact is established. For remote installation, so-called RAT applications are most often used, or remote access trojans, which most often arrive via a messenger as APK files. In the NFCGate being installed, as I said, Relay Mode is already running. The server settings are specified, where the NFC data is sent when the NFC tag is scanned by the victim's own smartphone. And at that moment, the suspect's device is likewise running an identical application in Relay Mode. And he's basically waiting for the victim to launch it, so he can move on to the next stage. And so, basically, the device, here are the screenshots in front of you, on the suspect's device NFCGate is running in the so-called Tag role. Hard to see, but here's the Tag role, and on the victim's side, the Reader role. And how, after all, is he to know he can already move on to the next stage, and that the victim has actually launched the app, and not just stringing him along over the phone, so to speak, saying "yes, yes, I've launched it, all good, we can move on." Essentially, he sees that this session is open — you see, here's the little green one, it's hard to see there, the label signals to him "Network Connect to Partner", so the connection is established correctly, we can move to the next stage. And the next stage of the attack is reading the card data, intercepting this traffic during authentication at the ATM over the NFC protocol. And essentially, at this stage the attackers are, as I've already said, next to the ATM and hold their own device with NFCGate up to the terminal, and all that's left is to enter the bank card PIN. And here, after all, how do they also get the PIN from the victim's side? Well, essentially, it can be, the same old social engineering can be used, or virtual keyloggers, which record the victim pressing the virtual keys, right, and using those same RAT applications they send this information to the suspect's side. In some NFCGate modifications there pops up an additional window that requires entering the PIN. So here it's already the victim himself, who — well, most often when using those apps that mimic banking apps. So here it is effectively the victim himself who hands the data over to the other side. And after a successful scan, essentially, the suspect gains access to the personal account and can withdraw the funds. The next stage, well, the final one rather, not the next, is the reuse of this intercepted traffic using Replay Mode, as we've already said. That is, re-emulating the operation of the bank card. As I've already said, the new wave of attacks using NFCGate most often happens by distributing APK files that emulate the operation of legitimate apps, either a government agency or a banking app. And there's a common pattern observed when dealing with such applications. That is, most often we see the UI being changed by creating a stylistically similar graphical interface. The fraudsters try to hide push notifications so as to effectively prevent detection and a timely response by the victim to the emerging threat. Next, we see changing app package names, changing the format of the collected data. Well, essentially, as I've also already said, in some modifications an additional prompt pops up to enter the PIN for the victim's bank account when the app is launched. Well, and essentially, let's go through the theory in practice. Okay, a real case. In this modification the mode was preset, the NFC operating mode, to Relay Mode. After that the data was sent to the attacker's server. Here, essentially, is the scheme in brief. A call came in via Telegram. An unknown person introduced himself as a law enforcement officer. And under the pretext of keeping the money safe asked the victim to install a certain app. Then he gave instructions on how to launch it and what to do with the bank card. Then he recommended deleting this app. And as a result, funds were withdrawn from the victim's account in the amount of 230,000 rubles. And what came in for forensic examination was a Redmi Note 11S mobile phone. Well, essentially, let's go through the steps the forensic expert took. To begin with, using our software, Mobile Criminalist Expert Plus, an advanced file system extraction of the device was performed; specifically, the MTK Android method worked successfully. Since, as we've already said, these apps are detected by most antivirus applications, right, we performed a scan of the file system structure of the extraction, and, essentially, a file called vtb1 was found, which was detected as a trojan. Essentially, looking at the directory, you can see it was created, modified on 22.01.25 at 10:20. And from the directory you can see that this file was found in a directory associated with Telegram. We can assume that it, most likely, arrived on the device in the course of a chat via the messenger. Moving on. Essentially, when analyzing the contents of a database table located in the directory associated with Telegram, you can see that this vtb1 file was received from a Telegram user with ID 7 and so on. We've hidden part of the identifiers because I'm not sure how unique they are. Well, still, when it's a real case, to rule out any complications, I'll just comment on it. In the next table, note that we — the expert — found the identifier of the downloaded file, with the value 52, then 93. Then, by this identifier, 52, 93, when analyzing the contents of another database, cache4.db, also registered in the directory associated with Telegram, the date of receipt of the message with this malicious file was established. Note: 22.01.25 10:20:44. And if we go back a step, it matches the modification date of this file in the Telegram directory. Essentially, once it became clear where and how this little beast came from, all that was left was to see what it actually is. Well, the next stage. After decompiling the vtb1 file, in the manifest XML the application identifier "Darmstadt" was found. Note, it isn't highlighted for us. Let's try. Here it is, the identifier of this app, if you can see the pointer. The name for this identifier is also displayed in the AppName parameter, VTB Protection, in the XML file as well. And we also identified — we've masked it too — here we identified the IP address of the server that the intercepted NFC data was actually being sent to. What else is notable here? Further examination of the trace picture this app left in the smartphone's operating system showed it was uninstalled from the device twice, on 23.01.25 at 11:16 and 11:41. And the install history of this app is also fully consistent with the timeline, starting from the date the malicious file was received. Next, in a directory related to the device's file system, there's a record of the NFC system service starting, which also indirectly confirms that this technology was in use on the device. And finally, in a directory related to mobile banking, we found an image file with a record of a withdrawal of 230,000 rubles, which, I suppose, confirms that the theft of the funds was completed. And in conclusion — prevention matters too, I think — we suggest a few simple rules that help protect against carding, as it's called. First of all, you should install apps only from official stores; don't share your bank card details with strangers and don't enter them on any suspicious websites or in apps. If you get a link to install or update a banking app, the first thing to do is probably to call the bank's hotline and check whether that offer is genuine at all. And if the bank card has been compromised after all, try to block it as quickly as possible, likewise via the hotline, or through the official banking app. To finish, I'd like to quote the greatest swindler of all time. But not all of you know this film — "The Twelve Chairs". The financial abyss is the deepest of all abysses — you can fall into it all your life. So may your service be the anchor that keeps ordinary citizens from falling in because of vulnerabilities like NFCGate and its derivatives. Thank you. *[applause]* Dima, there's a colleague up front here. Alexey, you wrapped up awfully quickly there. Thanks for the talk. My name's Alexey too, by the way. Here's my question. Does the NFC app leave digital traces when it operates in Clone Mode and Relay Mode? I mean, you said — when they walk up to someone. You've just described the traces of what the victim installed on their own device through Telegram. But if I understood you correctly, in NFC Clone Mode, the attacker just walks up to the victim, right? Not as such, no. It's more about the trace side of operating system artifacts, of the NFC technology itself starting, but there are very few of them. So they don't leave traces on the device? Effectively, no. And in Relay Mode, when there's an intermediary? No, Relay Mode is exactly this case. Yes, here there'll be one — the trace picture. — Relay Mode, there will be. You also mentioned Replay? No, Relay. Relay. In Relay there will be. In Capture Mode there won't be — there'll be very few. But in Relay there definitely will be. — — Those modes — do cases with those modes come up at all? Any practice out there, heard of any? Honestly, it was a real stroke of luck that we got a case like this at all. I think — someone may correct me — there aren't that many. And, in fact, probably not that many devices end up submitted for examination. Maybe someone here has a different experience? No, we get plenty of APK files. Where I'm from, we get them all the time — at least once a month for sure. — — No, but actually... More often, actually, we get victims coming to us who installed an APK file, and then afterwards the attacker told them to delete it, and then we try to go down the same route through the EKC. Well, I think if you have the victim's device, you'll definitely find the trace picture. I was just curious about this particular case. In Relay you'll definitely find it. Clone Mode. Thank you. — — I see a hand, on my way. — — Hello. Two quick questions. You said a reader is used — that it could be used on public transport, for instance. And you also said NFC works at a range of 3 to 4 centimeters. Is that range enough, on public transport, say, to read the data, with that many people around — that's one point. Or maybe there are some antennas, amplifiers — so that's question one. — — Well, we probably don't have that much expertise here in that respect. We didn't do that examination ourselves — this is information that one of our users shared with us. But judging by the information we have, in principle, it is realistic to read the data. So that data, even without a PIN code, is enough to carry out some sort of... To read the tag, yes. — — And to carry out some transactions. Effectively, yes. — — Thank you. That's one. And the second question. You also touched on SuperCard X, that it's positioned as legitimate or actually is legitimate — did I get that right — as a contactless payment app, that is. — — That's right. So how do you tell, in that case? You said it sends... A range of modifications, only here based on that app, just like the ones based on NFCGate — its derivatives. Ah, so it's not the original app? Not in its pure form, of course. NFCGate too... Built on it. Yes, of course. Thank you. — — Right, Nikita, could you go over, please. Good afternoon, thanks for the talk. I have a question. You mentioned that besides Relay Mode, Replay Mode is also used in attacks. Can you give any examples of this type of attack? — — Once more, louder please. Besides Relay Mode, Replay Mode is used for attacks. Are there any examples of actual real-world attacks using that mode? — — Well, we don't have that information. Yes, we can't give an example in that sense. But essentially, like I said, it's the same mode of retransmitting that signal multiple times. That is, having recorded the data once, you can use it over and over. Sorry, in that mode, as I understood it, there's also the security code, generated fresh for each transaction. How can that be reused afterwards? No, not the security code — the bank card PIN. No, no. I mean the security code specifically: when we pay via NFC, a new security code is generated every time. Ah, the one-time one? Yes, the one-time code. So how did you copy it, when it's different each time? How does that work? Well, that only works via social engineering, when the victim is on the phone. And then it works. Right, I see a hand there. *[music]* What a shame there are no users in the room, right? The roast hasn't even started yet, and the battle's already about to kick off. — — Thanks a lot for the interesting talk. A question about the antivirus. It detected it on the workstation where the examination was done. If it had been running on the phone itself at the time, would it have detected it on the phone, or would it have missed it because of a sandbox or something? — — It would. It would on the device too. — — Okay, thanks. — — Colleagues, more questions. Up front, Nikita. — — Where? Artem, as far as I remember. — — We know our regulars by sight. Good afternoon. SQL question. As I understand it, you parsed all those values in the SQL databases by hand. Do you have a reference guide anywhere, with a list of all the files and what's stored in them? Like, this file is responsible for this, this file stores this kind of data, that file stores that kind of data. Because we also have to search for a lot of things. Manually. — — Some of that information is available, but for this case it was manual only. The forensic expert did the work, I gather. — — So that's the question. Could you release a reference guide like that, with information about which data is stored in which file in the apps? We'll try; maybe we'll add it to the list of requests. The most honest answer. We'll try, but we're not promising. Nikita, did you see the hand there? Definitely, yeah. No, we're preparing a lot of things this year in general. The speaker's feeding back, I'll step aside. We're preparing a lot of materials, but we'll try — no promises. — — Good afternoon. Hello. Here's my question: is it possible to copy an NFC tag, say, on a device, on one Android device, let's say, with installed… Could you raise the mic a bit, please, it's hard to hear. …payment apps, like Mir Pay or a payment sticker, and the attacker clones it with a second device? In theory it's possible, but in practice we haven't tried it. — — Yuri Mikhailovich, there's still the roast, the time for battles, let's leave it for later. Go ahead. For the roast? — — No, why? One more question is fine, but if a fight breaks out now, it'll be on you — and on Nikita. — — I just wanted to clarify. You showed a slide where an APK file was scanned with Kaspersky, specifically. Was that the Kaspersky built into the MKO software, or a separate standalone one? It was separate, yes, but we can do this inside the product, in the "Malicious Objects" section. So now this is our integration with Kaspersky, so you can… Unfortunately, I've seen cases where it doesn't always… — — Anyway, those databases are up to date in the customer portal, so update them. That's the only advice I can give here. Thank you. I don't know why Alexey looked at me. The database is up to date, update it, all good, we check it. OK, colleagues, the rest of the questions go to the roast. Let's give Alexey a round of applause. Alexey, well done. Thank you very much.