The New Era of Carding: NFC Relay Attacks

▶ Watch (4:16)

Carding has evolved. NFC relay attacks bypass chip security by exploiting the convenience of contactless payments. Valentini cited a 35-fold surge in NFC relay fraud comparing the second half of 2024 to the first half of 2025. Early implementations like the Ngate malware, disclosed by Hazette in 2024, have given way to more sophisticated, commercialized platforms. Chinese-speaking threat actors now dominate this space, pushing the attack vector from theoretical to real-world incidents. Two Ukrainian teenagers were arrested in Poland for conducting NFC relay fraud against Polish citizens.

Supercardex: The First MaaS for NFC Relay

▶ Watch (7:01)

Supercardex is the first documented NFC relay malware offered as a fully commercialized malware-as-a-service platform. Cleafy’s team tracked it from early 2025. The platform operates through a Telegram channel run by Chinese-speaking actors. Subscription tiers range from $500 to $2,000 per month, depending on features. Affiliates receive technical support and regular updates. The malware does not abuse Android accessibility services. It uses only NFC and internet permissions to relay card data, making detection harder. Detection rates are lower than typical banking trojans.

The Attack Chain: Social Engineering Meets Malware

▶ Watch (8:25)

The attack starts with SMS phishing campaigns. Messages claim a wire transfer was accepted and ask the victim to call a number. Once the victim calls, the fraudster follows a playbook to determine the victim’s device type. If Android, they convince the victim to install a third-party app (Supercardex) via a link sent during the call. The fraudster then extracts the card’s PIN by having the victim open their banking app. They also persuade the victim to remove any spending limits. The victim is then told to place the physical card behind the phone, enabling the NFC reader.

Real-Time Relay Demo

▶ Watch (14:01)

The speakers showed a video recorded by the threat actors themselves. Two Android devices run Supercardex: one victim device, one receiver device. Both log in with the same credentials to link them through the command-and-control infrastructure. When the victim places a card behind their phone, the receiver device instantly receives the card data. The fraudster then uses a POS terminal to authorize a transaction in real time. The video shows a small test transaction approved without a PIN. The relay data is valid for only a few minutes and can be used once.

Old-School Malware Tries to Add NFC Relay

▶ Watch (18:10)

Alessandro Strino explained that fully featured malware like Droidbot and Copibara attempted to embed NFC relay capabilities. After Cleafy exposed Droidbot in late 2024, its operators shut down but later returned with a new bot claiming NFC relay support. However, the delivered sample was Copibara, not a new bot. Analysis revealed NFC relay code in Copibara, but it did not work. The developers admitted failure. Despite this, the command-and-control panel of Copibara included an NFC data tab, showing genuine interest. The challenge is that integrating NFC relay requires changing the entire fraud model.

The Future Landscape Splits in Two

▶ Watch (30:00)

Strino predicted a split. Old-school malware families will continue without NFC relay because adding it would raise detection rates and force a business model change. Newcomers will design malware specifically for real-time NFC relay fraud, with a streamlined attack from first contact to cash out. Defenders must move beyond IOC-based monitoring and start predicting attack patterns. The real-time nature of NFC relay reduces the time window for detection and response.

Q&A

How long is the NFC relay data valid? The data expires after a few minutes and can be used only once. ▶ 32:02

How do fraudsters cash out in countries without NFC ATMs? They use a network of money mules in other countries, like Spain, who receive the relayed data in real time and withdraw cash locally. ▶ 34:20

Can the fraud manager switch money mules if a transaction fails? Yes, the system allows instant switching to another mule, and the victim can be asked to try again, sending money to a different mule. ▶ 37:08

Notable Quotes

we see a surge in NF NFC relay froze frauds over 35 folds Federico Valentini · ▶ 4:16

supercardex was um firstly dis publicly disclosed by our team just a couple of months ago Federico Valentini · ▶ 7:01

the detection rate is lower to the mean if compared to motor bank intrusion Alessandro Strino · ▶ 18:10

this is a completely novel model to perform frauds Alessandro Strino · ▶ 28:52

we will see in the upcoming futures uh the landscape split in two sides Alessandro Strino · ▶ 30:00

Key Takeaways

  • NFC relay fraud surged 35x between H2 2024 and H1 2025.
  • Supercardex is the first commercial MaaS for NFC relay, with subscriptions up to $2,000/month.
  • The attack chain combines SMS phishing, phone social engineering, and real-time card data relay.
  • Old-school malware families tried but failed to integrate NFC relay due to business model conflicts.
  • Defenders must shift from IOC hunting to predicting attack patterns in real-time fraud.

About the Speaker(s)

Federico Valentini leads the Threat Intelligence Team and Incident Response at Cleafy. He oversees monitoring and uncovering new threats and attack patterns used by malicious actors. He has spoken at HackInBO 2022, Botconf 2023, Cert-EU 2023, BSides Cyprus 2023, FS-ISAC 2024, Botconf 2025, and other private events.

Alessandro Strino works as a senior malware analyst at Cleafy. His research focuses on binaries, computer forensics, binary exploitation, reverse engineering, and privilege escalation. He has spoken at Botconf 2023, Cert-EU 2023, BSides Cyprus 2023, FS-ISAC 2024, and Botconf 2025.