The Interior Ministry told about the fraud scheme using the malicious NFCGate
Fraudsters in Russia use malicious applications to deceive victims by posing as employees of banks, law enforcement agencies, or tech support. This was reported on September 9 in the Telegram channel of the Department for the organization of the fight against the illegal use of information and communication technologies of the Ministry of Internal Affairs of the Russian Federation.
"One of the most technologically advanced ways to withdraw victims' funds is using malicious software from the NFCGate family," the report says.
In this modification, called "reverse NFCGate," fraudsters create a hidden copy of the card on the victim's device, which is called a "drop card."
The scheme works as follows: attackers ask the victim to install a malicious application on the phone, ostensibly to protect funds or block unauthorized operations. Further, under the pretext of transferring funds to a secure account, the victim is persuaded to approach an ATM with an NFC function. When a person puts a phone to an ATM, the program emulates the fraudster's card, and the funds are transferred to the attackers' account.
At the same time, the victim himself, by entering a PIN code and confirming the operation, sends money to the scammers, not realizing that he is doing this of his own free will.
Attackers often ask to remove malware in order to hide their tracks and avoid further investigation. This scheme allows you to bypass the protection of banks, as the operation looks legitimate, which does not arouse suspicion from anti-fraud systems. The money is instantly credited to the scammers' account and quickly cashed out.
On September 8, a new fraud scheme was reported, according to which fraudsters offer the victim to contact a false participant. During a conversation with an alleged law enforcement official, Russians are persuaded to transfer funds, which eventually end up in the hands of the attackers.
All important news is on the Izvestia channel in the MAX messenger.
Переведено сервисом «Яндекс Переводчик»