Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Amazon buys Fauna Robotics, maker of the Sprout humanoid robot that can dance and pick up toys

Amazon buys Fauna Robotics, maker of the Sprout humanoid robot that can dance and pick up toys

29 March 2026
Private equity is eying Asia’s healthcare funding gap as countries get wealthier and older

Private equity is eying Asia’s healthcare funding gap as countries get wealthier and older

29 March 2026
The Iran and Ukraine wars are converging as combatants increasingly overlap

The Iran and Ukraine wars are converging as combatants increasingly overlap

29 March 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » New Android Warning — This TOAD Malware Attack Steals Cash From ATMs
Innovation

New Android Warning — This TOAD Malware Attack Steals Cash From ATMs

Press RoomBy Press Room22 April 20253 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
New Android Warning — This TOAD Malware Attack Steals Cash From ATMs

Most Android malware is after one thing: your passwords. That’s just the way it is these days, with infostealer malware firmly at the top of the cyber attack tree. Some attacks can lead directly to attacks on your bank balance, as recently detailed in a new report warning of smartphone PIN code threats. Now, it would seem, one group of threat actors has moved things up a gear or two with a complex campaign involving Android malware, a telephone-oriented attack delivery methodology, and, ultimately, the theft of your cash from ATMs.Welcome to the weird and worrying world of SuperCard X TOAD attacks.

The Great Android ATM Heist

Threat intelligence experts Federico Valentini‍, Alessandro Strino and Michele Roviello, from fraud detection platform Cleafy, have reported how a “new and sophisticated Android malware campaign” called SuperCard X is intercepting and relaying near field communication messages from compromised devices to facilitate fraudulent ATM cash withdrawals. Yes, really. This malware can steal cash from ATMs.

“The innovative combination of malware and NFC relay empowers attackers to perform fraudulent cash-outs with debit and credit cards,” the researchers said, adding that it has demonstrated high success rates when targeting contactless ATM withdrawals.

The attack execution begins with, you guessed it, targeting social engineering tactics. The phishing messages, typically delivered by way of SMS or WhatsApp, use brand impersonation to leverage trust and add the necessary urgency to the fraud. By alerting victims to a suspicious outgoing payment, which is purported to be a bank fraud security alert, the user is prompted to call a support telephone number as a matter of some urgency. This is where the TOAD enters the equation. A telephone-oriented attack delivery allows the fraudsters to manipulate victims directly during phone conversations.

In the case of SuperCard X attacks, that manipulation flows as follows:

  • The victim is directed to reset their payment card PIN code.
  • They are then instructed to remove existing spending limits.
  • Then, a malicious app, disguised as a verification tool, must be installed, and this is where the SuperCard X malware with NFC-relay functionality arrives.
  • Finally, the victim has to take their physical payment card into proximity of their now-infected Android device, where the card details are silently captured.

The clever bit, assuming all of that social engineering has been successful, is that those card details are relayed in real-time to a second, attacker-controlled Android phone, used to make the contactless ATM withdrawals.

Security Expert Comments On SuperCard X Android TOAD Attack

If this threat expands, Randolph Barr, chief information security officer at Cequence, told me, it will likely be due to users falling victim to social engineering and being convinced to disable built-in security protections. Obviously, that’s a massive red flag, as no legitimate organization would ever ask you to do such a thing. “This attack highlights the importance of understanding what an app does before installing or sideloading it,” Barr said while advising that Google Play offers protections against such malicious apps and should be used rather than introducing the risk of sideloading applications from other sources. “There are ways to recognize and prevent TOAD-style attacks,” Barr concluded, suggesting that validating the legitimacy of any such request before acting on it is a great starting point.

A Google spokesperson confirmed this advice in a statement: “Based on our current detection, no apps containing this malware are found on Google Play. Android users are automatically protected by Google Play Protect, which is on by default on Android devices with Google Play Services.”

android malware ATM Cash Hack Cleafy Google malware Payment Card Theft smartphone SuperCard X TOAD
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Meta promised it wouldn’t spy on you with its AI smart glasses. A lawsuit says humans are watching you, actually

Meta promised it wouldn’t spy on you with its AI smart glasses. A lawsuit says humans are watching you, actually

27 March 2026

Why A $2.4 Billion Biotech Fund Filed For Bankruptcy Over $500K

26 March 2026
A court just ruled that tech addiction is real—and dangerous. It could be Meta and YouTube’s Big Tobacco moment

A court just ruled that tech addiction is real—and dangerous. It could be Meta and YouTube’s Big Tobacco moment

25 March 2026
From M Startup To AI Powerhouse: Jennifer Tejada’s PagerDuty Playbook

From $50M Startup To AI Powerhouse: Jennifer Tejada’s PagerDuty Playbook

25 March 2026

The Billion-Dollar Robot Race Is Moving Faster Than The Robots

25 March 2026

Indian Pharma Billionaires Pile Into Generic Weight-Loss Drugs, Sparking Regulatory Scrutiny

25 March 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
Moltbook is the talk of Silicon Valley. But the furor is eerily reminiscent of a 2017 Facebook research experiment

Moltbook is the talk of Silicon Valley. But the furor is eerily reminiscent of a 2017 Facebook research experiment

6 February 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Russia expected a windfall from soaring oil prices, but Ukrainian drones are devastating exports

Russia expected a windfall from soaring oil prices, but Ukrainian drones are devastating exports

29 March 20261 Views
Global economy takes gut punch from war in Iran, with nobody untouched the longer it goes on

Global economy takes gut punch from war in Iran, with nobody untouched the longer it goes on

29 March 20261 Views
‘There are a lot more attacks happening that aren’t being reported’: Iran’s cyber response creeps across the globe

‘There are a lot more attacks happening that aren’t being reported’: Iran’s cyber response creeps across the globe

29 March 20261 Views
AI is so sycophantic there’s a Reddit channel called ‘AITA’ documenting its sociopathic advice

AI is so sycophantic there’s a Reddit channel called ‘AITA’ documenting its sociopathic advice

29 March 20261 Views
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Amazon buys Fauna Robotics, maker of the Sprout humanoid robot that can dance and pick up toys

Amazon buys Fauna Robotics, maker of the Sprout humanoid robot that can dance and pick up toys

29 March 2026
Private equity is eying Asia’s healthcare funding gap as countries get wealthier and older

Private equity is eying Asia’s healthcare funding gap as countries get wealthier and older

29 March 2026
The Iran and Ukraine wars are converging as combatants increasingly overlap

The Iran and Ukraine wars are converging as combatants increasingly overlap

29 March 2026
Most Popular
Yahoo CEO Jim Lanzone on ‘the white whale of turnarounds’ and turning to AI—licensed from Anthropic

Yahoo CEO Jim Lanzone on ‘the white whale of turnarounds’ and turning to AI—licensed from Anthropic

29 March 20262 Views
Russia expected a windfall from soaring oil prices, but Ukrainian drones are devastating exports

Russia expected a windfall from soaring oil prices, but Ukrainian drones are devastating exports

29 March 20261 Views
Global economy takes gut punch from war in Iran, with nobody untouched the longer it goes on

Global economy takes gut punch from war in Iran, with nobody untouched the longer it goes on

29 March 20261 Views
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.