A newly discovered malicious Android application named VIPER is being sold on dark web cybercrime forums. This mobile tool abuses legitimate NFC APIs to scan, capture, and clone physical credit card data, operating invisibly in the background with automatic persistence.


High-risk Android threat leveraging Host Card Emulation to harvest physical contactless card records.
Social engineering via SMS/WhatsApp links leading to sideloaded custom APKs.
Manual installation requesting NFC access and boot-completion broadcast receiver registration.
Launcher icon is hidden immediately after execution to run invisibly as a background service.
Device scans physical credit/debit cards within proximity, extracting Track 1 & Track 2 EMV records.
Harvested cards are cached and transmitted over encrypted channels to the actor's admin panel.
If your team may be exposed to a similar threat, FemtoSec can help validate blast radius, prioritize remediation, and connect the issue to a practical security program.