1b8e91037937886b59582a1e…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

NFC Relay (provisional). Android NFC-relay fraud malware. Running on a victim’s phone, it reads contactless bank-card/tag data over NFC and relays it in real time over a WebSocket channel to an attacker-controlled device, which replays it at a payment terminal or ATM for fraudulent transactions (an NFSkimming / “NGate”-style technique). The relay C2 (where captured card APDUs, device status and the victim 4-digit PIN are pushed over a WebSocket) is wss://dashboard.gripe/ws-relay in the current build and ws://178.236.243.8:3050 in an earlier com.example.myemulator build. dashboardcloud.app is the operator WebView phishing-UI host (loaded via webView.loadUrl with a Portuguese ?step= flow and an “Android” JS bridge) - tracked as a panel, not the relay. api.dashboardcloud.app (painelStatusUrl) is assigned in the dex but never contacted, so it is NOT recorded as a C2. One widely repackaged build (identical classes.dex; lure label “Nfc Security”, package app.nfcsecurity.vault, Portuguese UI) stores its endpoints character-reversed and un-reverses them via UtilZ0Y480.decode, with source-to-sink bs.getWsUrl() -> SERVER_URL -> OkHttp newWebSocket(); it also carries a dormant base64+XOR alternate config (ws/web/api.cupworldcup.site) that the getters never use, so that is not treated as a live C2. Family label provisional. Indicators: wss://dashboard.gripe/ws-relay, https://dashboardcloud.app.

Recovered configuration

backend_urls
https://dashboardcloud.app, https://api.dashboardcloud.app/api/status
build_id
2363b211bfb1
config_id
e69ea27c
relay_c2
wss://dashboard.gripe/ws-relay

Source: string-reversed URLs in dex (bs config, UtilZ0Y480.decode = reverse)

Identification

SHA-256
1b8e91037937886b59582a1eb14f0fa597811ab0884f44285c0c4a88cec99e86
MD5
f8a0677ce4ec1af77e29e4c61d829779

Observed

Families
NFC Relay (provisional)
First seen
2026-10-10

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
dashboard.gripe/ws-relay domain - wss NFC Relay (provisional) 2026-10-10
dashboardcloud.app domain - https NFC Relay (provisional) 2026-10-10

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
0781333c7202530437e9304722e36c9f9ddb01746e805fb0da690fc74d0b71ed

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About NFC Relay (provisional)

Android NFC-relay fraud malware. Running on a victim's phone, it reads contactless bank-card/tag data over NFC and relays it in real time over a WebSocket channel to an attacker-controlled device, which replays it at a payment terminal or ATM for fraudulent transactions (an NFSkimming / "NGate"-style technique). The relay C2 (where captured card APDUs, device status and the victim 4-digit PIN are pushed over a WebSocket) is wss://dashboard.gripe/ws-relay in the current build and ws://178.236.243.8:3050 in an earlier com.example.myemulator build. dashboardcloud.app is the operator WebView phishing-UI host (loaded via webView.loadUrl with a Portuguese ?step= flow and an "Android" JS bridge) - tracked as a panel, not the relay. api.dashboardcloud.app (painelStatusUrl) is assigned in the dex but never contacted, so it is NOT recorded as a C2. One widely repackaged build (identical classes.dex; lure label "Nfc Security", package app.nfcsecurity.vault, Portuguese UI) stores its endpoints character-reversed and un-reverses them via UtilZ0Y480.decode, with source-to-sink bs.getWsUrl() -> SERVER_URL -> OkHttp newWebSocket(); it also carries a dormant base64+XOR alternate config (ws/web/api.cupworldcup.site) that the getters never use, so that is not treated as a live C2. Family label provisional.