Carding is Dead, Long Live Carding

Federico Valentini (Threat Intelligence and Incident Response Leader · Clifi), Allesandro Strino (Clifi)

DEF CON 33 · Day 1 · Main Stage

Overview

This talk, "Carding is Dead, Long Live Carding," delivered by Federico Valentini and Alessandro Strino from Clifi, delves into the alarming evolution of credit card fraud, specifically highlighting the surge in NFC relay attacks fueled by Malware-as-a-Service (MaaS) platforms. The speakers present a comprehensive analysis of how sophisticated cybercrime operations are exploiting contactless payment technologies, moving beyond traditional carding methods to a more dynamic, real-time fraud model.

Watch on YouTube

Visual summary for Carding is Dead, Long Live Carding by Federico Valentini, Allesandro Strino
Visual summary for Carding is Dead, Long Live Carding by Federico Valentini, Allesandro Strino

Key moments

  1. 0:00 Welcome and Introduction to Carding is Dead
  2. 1:30 Defining Carding: History and Financial Impact
  3. 3:00 Entering a New Era: The Rise of NFC Relay Attacks
  4. 4:00 Explosive Growth and Sophistication of NFC Relay Malware
  5. 5:00 Documented Real-World NFC Relay Fraud Cases
  6. 6:30 Supercardics: First Commercialized NFC Relay MaaS Platform
  7. 8:00 Analyzing the Full NFC Relay Attack Chain (Phishing)

Carding is Dead, Long Live Carding

Speakers: Federico Valentini (Threat Intelligence and Incident Response Leader, Clifi); Alessandro Strino (Clifi)

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=JSDwexw90zs

Overview

This talk, "Carding is Dead, Long Live Carding," delivered by Federico Valentini and Alessandro Strino from Clifi, delves into the alarming evolution of credit card fraud, specifically highlighting the surge in NFC relay attacks fueled by Malware-as-a-Service (MaaS) platforms. The speakers present a comprehensive analysis of how sophisticated cybercrime operations are exploiting contactless payment technologies, moving beyond traditional carding methods to a more dynamic, real-time fraud model.

The presentation provides critical insights into the operational mechanics of these new threat actors, detailing the technical architecture, social engineering tactics, and cash-out mechanisms employed. It underscores why this shift matters profoundly to the financial industry and individual consumers alike: NFC relay attacks bypass security features designed for chip cards, exploit user convenience, and are becoming increasingly commercialized and accessible to a wider range of threat actors. The talk serves as a stark warning about the future of financial fraud and the urgent need for adaptive defensive strategies.

Background

▶ Watch: Welcome and Introduction to Carding is Dead (0:00)

Historically, carding has been a cornerstone of cybercrime, involving the unauthorized trafficking and use of credit card data, generating billions in losses annually. This landscape was largely dominated by sophisticated Eastern European cybercrime gangs adept at various fraud scenarios, including card-not-present (CNP) fraud and skimming. These groups often operated sophisticated cybercrime forums for trading and selling stolen data.

However, the defensive landscape has evolved significantly. The widespread implementation of security measures like 3D Secure (3DS) and sophisticated behavioral analysis performed by anti-fraud teams has made traditional carding more challenging. This shift has prompted new threat actors, particularly Chinese-speaking groups, to innovate and revolutionize the exploitation of contactless payment systems. This marks the dawn of a "new era of carding," where NFC relay attacks represent a significant evolution. These attacks bypass the inherent security of chip cards by exploiting the very convenience features designed into Near Field Communication (NFC) technology. Data indicates a dramatic surge in NFC relay fraud, with a 35-fold increase observed between the second half of 2024 and the first half of 2025. Early implementations of NFC relay malware, such as Ngate (disclosed by Hazette in late 2024), paved the way for more sophisticated platforms like Supercardics. Real-world incidents underscore the immediate threat, with arrests reported in the US (against Chinese nationals) and Poland (against Ukrainian citizens) for perpetrating "tap-to-pay" fraud using mobile devices, confirming that these are not theoretical attacks but active, revenue-generating operations.

Key Findings

▶ Watch: Entering a New Era: The Rise of NFC Relay Attacks (3:00)

The core of the talk revolves around Supercardics, the first documented NFC relay malware that operates as a fully commercialized Malware-as-a-Service (MaaS) platform. Clifi's team began tracking Supercardics in early 2025, discovering a sophisticated operation promoted via Telegram channels by Chinese-speaking threat actors. This platform offers various subscription tiers, technical support, and regular updates to its affiliates, with pricing models ranging from $500 to $2,000 per month depending on the features included in the customized malware builds.

Clifi's extensive visibility, working with multiple financial institutions, allowed them to reconstruct the entire fraud chain, from initial phishing attempts to the final cash-out mechanisms. The attack fundamentally blends social engineering with malicious software components. It begins with smishing campaigns (e.g., "Dear client, your wire transfer has been accepted... if not you please call the following number"). When victims call back, threat actors engage in a social engineering playbook to understand the victim's device and context. If an Android device is identified, they proceed with an NFC relay fraud.

The social engineering phase is critical for success, requiring several key steps:

  1. Malicious Application Installation: Victims are convinced to install a "secure application" (Supercardics) by clicking a link sent during the phone call.
  2. PIN Code Retrieval: Since NFC relay itself cannot extract the card's PIN, threat actors manipulate victims into revealing it, often by guiding them to retrieve it from their banking application.
  3. Credit Card Limit Removal: Victims are convinced to temporarily remove credit card transaction limits, clearing the path for larger fraudulent transactions.

Once these prerequisites are met, the NFC relay attack commences. The victim is instructed to place their physical card behind their phone, enabling the Supercardics malware to act as an NFC reader, dumping card data. This data is then sent in real-time over the internet to a dedicated Command and Control (C2) infrastructure. From the C2, the data is pushed to another Android device, termed a receiver device, managed by a threat actor or money mule. This receiver device, also running Supercardics, can then be used in real-time to withdraw money from NFC-enabled ATMs or make transactions at Point-of-Sale (PoS) terminals. The speakers noted that in Italy, where their investigation was concentrated, NFC-enabled ATMs are less common, leading the threat actors to leverage geographically distributed money mules, for example, cashing out in Spain while the victim is in Italy.

A significant finding related to Supercardics' operational sophistication is its low detection rate compared to other mobile banking malware. This is primarily because it avoids abusing accessibility services, a common tactic for many fully-featured Android malware families. Instead, Supercardics relies on legitimate NFC and internet connection permissions to execute its specific fraud pattern. Furthermore, the developers of Supercardics are highly responsive to affiliate feedback, constantly updating their software to streamline the victim onboarding process. For instance, an initial requirement for victims to manually log into the malicious application with a username and password was later replaced with hardcoded credentials in updated malware builds, simplifying the attack. This evolution led to a rebranding of Supercardics into a new iteration called Lion, which features a "fraud manager" lobby. This manager can monitor all active victims and money mules, allowing for real-time switching of mules if a transaction fails or a limit is hit, showcasing a highly flexible and efficient fraud system.

The talk also explored whether "old school" fully-featured malware (like RATs, sniffers, keyloggers) would integrate NFC relay capabilities. Their investigation into Droidbot and Copibara revealed an attempt. Droidbot, after an initial shutdown following Clifi's exposure, resurfaced with some developers joining the Copibara group. While Copibara briefly featured embedded NFC relay functionality and an "NFC data" tab in its C2, the implementation was ultimately unsuccessful and discontinued. This suggests that fully-featured malware, with its broader information-gathering goals and reliance on a different, often slower, fraud model, finds it challenging to seamlessly integrate the real-time, specialized fraud model of NFC relay attacks without a fundamental shift in its operational philosophy. The landscape is thus bifurcating: specialized NFC relay malware focusing on real-time fraud, and traditional malware continuing its broader data exfiltration and remote access operations.

Technical Deep Dive

▶ Watch: Explosive Growth and Sophistication of NFC Relay Malware (4:00)

The technical core of the Supercardics operation hinges on a two-device relay system facilitated by a central Command and Control (C2) infrastructure. The victim's Android device acts as the "sender" or "reader" component. Once the Supercardics malware is installed and launched on this device, and the victim is convinced to place their physical credit card (which must be NFC-enabled) against the phone's back, the malware leverages the device's legitimate NFC reader capabilities. It then dumps the card data – including primary account number (PAN), expiry date, and potentially other track data – from the physical card.

This captured data is not stored locally but is immediately encrypted and transmitted over the internet to the threat actor's C2 server. The C2 acts as a broker, receiving the real-time card data and forwarding it to the "receiver" device. The receiver device is another Android smartphone, also running a Supercardics build, but controlled by the threat actor or a money mule. This device essentially emulates the victim's physical card. When the money mule approaches an NFC-enabled ATM or PoS terminal and taps the receiver device, the terminal interacts with the malware as if it were the legitimate physical card. The C2 maintains the real-time link, ensuring that transaction requests from the terminal are relayed back to the original victim's card data (via the receiver device, C2, and back to the victim's card details). This entire process typically occurs within minutes, exploiting the brief window during which the contactless transaction is valid.

Initially, Supercardics required both the sender (victim) and receiver (mule) devices to log into the malicious application using the same username and password to establish the link with the C2. This step, identified as a friction point for affiliates, was later streamlined in updated versions. The developers hardcoded these credentials directly into the malware builds, eliminating the need for victim interaction and improving the attack's stealth and success rate.

The evolution to "Lion" further refines this operational model. The fraud manager interface provides a centralized dashboard for threat actors to oversee multiple ongoing attacks. It visually links "victim" icons (representing sender devices) with "money mule" icons (representing receiver devices) in a "lobby" system. This sophisticated management capability allows for dynamic, real-time adjustments. For example, if a transaction attempt with one money mule fails (perhaps due to a card limit, a suspicious activity flag, or the mule being compromised), the fraud manager can instantly switch the transaction to another available money mule in a different location, ensuring maximum cash-out efficiency. This global distribution and dynamic management highlight a highly organized and resilient fraud operation.

The investigation into Droidbot and Copibara provided a fascinating insight into the challenges of integrating this specialized NFC relay functionality into broader, multi-purpose Android malware. While Copibara's C2 panel briefly displayed an "NFC data" tab, indicating a clear intent to incorporate this feature, the effort was reportedly unsuccessful. The core issue likely lies in the fundamental difference in fraud models. Traditional RATs like Droidbot or Copibara focus on long-term device compromise, data exfiltration (credentials, SMS, call logs), and remote control, often with a more drawn-out information-gathering phase. NFC relay, by contrast, is a rapid, transaction-focused attack that requires a specific, real-time interaction flow that doesn't easily align with the broader, more passive data collection goals of a typical RAT. This divergence explains why specialized NFC relay MaaS platforms are emerging as distinct entities rather than simply being features embedded into existing, older malware families.

Demo / Proof of Concept

▶ Watch: Supercardics: First Commercialized NFC Relay MaaS Platform (6:30)

While the live audience at DEF CON faced technical difficulties and couldn't view the slides or video demonstration, the speakers meticulously described a proof-of-concept video created by the Supercardics threat actors themselves. This video was originally produced to promote the malware's capabilities to potential affiliates within their Telegram channels.

The demonstration showcased a laboratory setup involving two Android devices. The device on the right represented the victim's phone (sender device), and the one on the left represented the threat actor's or money mule's phone (receiver device). Both devices had the Supercardics application pre-installed. The video began with the threat actor opening the Supercardics application on both devices. The speakers explained that, in earlier versions, this phase involved logging in with the same username and password on both phones to link them to the C2 infrastructure. In later, updated versions, these credentials were hardcoded, simplifying the process.

Once the applications were linked, the threat actor placed a physical credit card behind the "victim's" phone. In real-time, the "receiver" device on the left displayed the credit card information being dumped from the physical card. The threat actor then used the receiver device to perform a transaction on a Point-of-Sale (PoS) device. The demonstration showed the PoS device successfully processing the transaction, accompanied by an audible confirmation sound indicating approval. The speakers clarified that this laboratory transaction involved a very small amount, which typically does not require a PIN, thus allowing the demonstration to proceed without that additional step. This clear, step-by-step video effectively illustrated the end-to-end functionality of the Supercardics NFC relay attack, from card data acquisition to real-time fraudulent transaction.

Defensive Implications

▶ Watch: Analyzing the Full NFC Relay Attack Chain (Phishing) (8:00)

The rise of commercialized NFC relay attacks like Supercardics demands a multi-faceted and proactive defensive strategy from financial institutions, security vendors, and end-users.

Firstly, user education is paramount. The success of these attacks hinges heavily on social engineering. Consumers must be educated about the dangers of clicking suspicious links in smishing messages, installing third-party applications from untrusted sources, and, critically, never sharing their PIN code or being convinced to temporarily remove credit card limits. They should also be aware that placing a physical card behind their phone while on a call with an unknown party can lead to fraud. Financial institutions should run public awareness campaigns highlighting these specific tactics.

Secondly, financial institutions must enhance their fraud detection capabilities. Traditional anti-fraud systems often focus on card-not-present fraud or large, anomalous transactions. NFC relay attacks, however, leverage real-time contactless transactions. Defenders need:

  • Advanced Behavioral Analytics: Systems should be capable of detecting unusual sequences of events, such as a sudden removal of a credit card limit followed immediately by a series of contactless transactions, especially across different geographic locations.
  • Real-time Transaction Monitoring: The rapid nature of NFC relay fraud necessitates real-time analysis of transaction data, looking for patterns indicative of relay attacks (e.g., multiple transactions in quick succession using the same card data but from different physical locations via receiver devices).
  • Predictive Threat Intelligence: Moving beyond reactive IOC-based detection, financial institutions need intelligence systems that can identify and predict emerging attack patterns and methodologies, such as the specific social engineering playbooks used by Supercardics affiliates.
  • Robust ATM and PoS Security: While NFC offers convenience, its exploitation means that ATM and PoS terminals with NFC capabilities need enhanced security. This could involve stricter limits for contactless transactions, mandatory PIN entry for all contactless transactions above a very low threshold, or additional multi-factor authentication for high-value contactless payments.
  • Cross-border Fraud Detection: The use of geographically distributed money mules (e.g., victim in Italy, cash-out in Spain) requires financial institutions to improve intelligence sharing and cross-border fraud detection capabilities to identify linked fraudulent activities.

Thirdly, Android platform security plays a crucial role. App stores must intensify efforts to detect and remove malicious applications like Supercardics. While Supercardics avoids accessibility service abuse, it still requires specific permissions (NFC, internet). Users should be trained to scrutinize app permissions during installation, even if they appear legitimate.

Finally, law enforcement and cybersecurity researchers must continue their collaborative efforts. Tracing MaaS platforms and their affiliates requires international cooperation given the distributed nature of these criminal enterprises. Sharing threat intelligence, including details on malware evolution, C2 infrastructures, and social engineering templates, is vital to disrupt these operations effectively.

Key Takeaways

  • NFC relay attacks represent the cutting edge of credit card fraud, rapidly growing and specifically targeting the convenience of contactless payments by bypassing traditional chip card security.
  • Malware-as-a-Service (MaaS) platforms like Supercardics and its successor, Lion, have commercialized these attacks, making them accessible to a broader range of threat actors through subscriptions, support, and regular updates.
  • Social engineering remains a critical component of the attack chain, requiring victims to be tricked into installing malicious applications, revealing their PINs, and temporarily removing credit card limits.
  • Modern NFC relay malware often achieves lower detection rates by avoiding common accessibility service abuses, instead relying on legitimate NFC and internet permissions to perform its specialized fraud.
  • The operational model for these attacks is highly optimized and real-time, featuring sophisticated "fraud manager" dashboards that allow for dynamic switching of money mules across different geographies to maximize cash-out success.
  • Defenders must shift towards proactive and predictive monitoring, enhancing behavioral analytics, user education, and cross-border intelligence sharing, rather than solely relying on reactive Indicator of Compromise (IOC) based detection.

About the Speaker(s)

Federico Valentini is the Threat Intelligence and Incident Response Leader at Clifi, an Italian-based software vendor. Clifi specializes in working with financial institutions to identify and counteract fraud scenarios impacting both individual consumers and corporate environments. His expertise lies in understanding the evolving landscape of cyber threats and developing strategies to protect financial systems.

Alessandro Strino is a key member of the Threat Intelligence team at Clifi. Working alongside Federico Valentini, Alessandro contributes to the in-depth research and analysis of cybercrime trends, particularly those affecting the financial sector. His work helps reconstruct complex attack chains and understand the technical intricacies of new malware families like Supercardics.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Solid original research on a real, fast-moving threat that most of the industry hasn't caught up to yet. The 35x growth figure is a headline, but the actual value here is the operational reconstruction of Supercardics/Lion as a MaaS platform — pricing tiers, affiliate UX improvements, the fraud manager lobby — that's intel you don't get from a press release.

Heather Calloway (CISO) — SOLID

A credible, well-documented piece of threat intelligence on a genuinely evolving fraud vector — NFC relay MaaS is real, growing fast, and underappreciated by most financial sector security teams. The research is solid, but the talk is built for researchers and analysts, not the fraud risk owners or security executives who need to act on it.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33