---
title: "NFCShare Android malware spreads via fake banking app updates on GitHub"
url: https://daily.dev/posts/nfcshare-android-malware-spreads-via-fake-banking-app-updates-on-github-dvfs6ijhu
source_url: https://www.bleepingcomputer.com/news/security/nfcshare-android-malware-spreads-via-fake-banking-app-updates-on-github
type: article
source: "BleepingComputer"
published: 2026-06-08T22:16:04.461Z
updated: 2026-06-08T22:16:25.484Z
tags: ["security", "phishing"]
reading_time: 3
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# NFCShare Android malware spreads via fake banking app updates on GitHub

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

New variants of the NFCShare Android malware are being distributed as fake banking app updates hosted on GitHub repositories. The malware targets customers of European banks, primarily in Italy and Spain, by tricking victims into scanning their payment cards near their device's NFC chip via a fake verification screen. It steals card numbers, expiry dates, card types, and 4-digit PINs, exfiltrating data to a C2 server over WebSocket for use in NFC relay payment fraud. Since April 2026, the GitHub repo has hosted 56 unique malicious APKs impersonating banks including Intesa, Banca Sella, Nexi, and CaixaBank. Newer samples also use malformed APK packaging to disrupt automated static analysis tools. Users are advised to install banking apps only from Google Play and enable Play Protect.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/nfcshare-android-malware-spreads-via-fake-banking-app-updates-on-github>

## Similar posts on daily.dev

- [NFC tap-to-pay gets tapped by hackers](https://daily.dev/posts/nfc-tap-to-pay-gets-tapped-by-hackers-qihxjff0m) · CSO Online · 0 upvotes · 0 comments
- [NGate Android malware uses HandyPay NFC app to steal card data](https://daily.dev/posts/ngate-android-malware-uses-handypay-nfc-app-to-steal-card-data-dx1ca6pjq) · BleepingComputer · 0 upvotes · 0 comments
- [RelayNFC Targets Brazil](https://daily.dev/posts/relaynfc-targets-brazil-mti8kp6z0) · Cyble · 1 upvotes · 0 comments
- [Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Fraud](https://daily.dev/posts/brazil-hit-by-banking-trojan-spread-via-whatsapp-worm-and-relaynfc-nfc-relay-fraud-lt4ojamt8) · The Hacker News · 0 upvotes · 0 comments
- [Android malware combo takes out loans and relays victims' credit cards](https://daily.dev/posts/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards-zkhg3khej) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/nfcshare-android-malware-spreads-via-fake-banking-app-updates-on-github-dvfs6ijhu)
