A particularly dangerous Android malware has emerged that can steal bank card information.
A new, highly sophisticated type of Android malware can exploit the near-field communication (NFC) technology built into phones to steal bank card information.
Imagine you receive a text message that looks like it's from a bank, notifying you of a "suspicious transaction" and suggesting you call customer service immediately. Out of caution, you comply. A calm, reassuring voice answers: "Don't worry, we'll guide you step-by-step."
Just minutes later, you've unwittingly fallen into the trap of cybercriminals, meaning you've had malware installed, provided your PIN, had transaction limits removed, and given permission to have your account data wiped clean. All of this happens under what seems like reasonable trust.

It's SuperCard X – a new generation malware variant, which experts from the Italian security company Cleafy warn is "almost invisible, extremely sophisticated and effective".
This type of malware is part of the "malware-as-a-service" (MaaS) model, developed by Chinese-speaking hacking groups.
SuperCard X exploits Android devices and uses NFC forwarding techniques to commit theft, steal card information, and even withdraw money before you even realize what's happening.
How does the SuperCard X malware work?
What makes SuperCard X particularly dangerous is its extremely sophisticated multi-layered attack capability. It all starts with a fake message, possibly an SMS, notifying you that your bank account has been compromised.
Next, the scammers directly call, using a polite and trustworthy voice to guide the victim. Once they've gained enough trust, they begin manipulating the victim, asking for their PIN, removing spending limits on their card, and installing a malicious app disguised as "advanced security."

The final tactic is a seemingly harmless but deadly trick: they ask you to touch your bank card to your phone "just for verification." In reality, the malicious app silently reads the data via NFC and transmits it to a card copying device controlled by the attacker. With the card copy in hand, they can easily withdraw money contactlessly at ATMs, leaving virtually no trace.
This scam campaign has been documented with victims in several countries such as Italy and the United States, involving cybercrime rings linked to China.
Previously, experts from the Slovakia-based cybersecurity company ESET also discovered Android malware that exploited NFC technology to attack users of three major banks in the Czech Republic.
The human element is key in the fight against malware.
What makes SuperCard X dangerous is not just its sophisticated malware, but the human element.
According to Randolph Barr, Director of Information Security at the US security company Cequence, the majority of current attacks still have a clear geographical focus, with indications that they are targeting a specific area.
He emphasized: "If this threat spreads, it will largely be because users are being manipulated by non-technical attacks, being persuaded to turn off built-in protection mechanisms, which is a worrying warning sign."
Another potential risk stems from the platform itself. Barr noted that the high percentage of Android users in Asia could make the region a more vulnerable target. This is because, in places where downloading apps from external sources is common, security barriers are inherently lower.
Android is appealing because of its flexibility, but that also opens the door to sophisticated scams like SuperCard X. Meanwhile, the iOS ecosystem, with its strict limitations, especially regarding NFC access, is better protecting users.
"Although sometimes criticized for being too restrictive, from a security perspective, these limitations are actually a valuable layer of protection," security expert Barr said.
Although malware is becoming increasingly sophisticated, non-technical attacks remain familiar "old tricks." Barr warned: "Android users need to be better aware of the signs of phishing; sometimes simply stopping to verify the legitimacy of a request is enough to avoid risk."