Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Interfaces Make Memories Useful, SNIA MRAM SIG And Everspin

Interfaces Make Memories Useful, SNIA MRAM SIG And Everspin

25 June 2026
Trump’s Iran war made the Senate symbolically vote to curb his war powers for the first time

Trump’s Iran war made the Senate symbolically vote to curb his war powers for the first time

25 June 2026
Qualcomm Lays Out New Data Center Roadmap For AI; Meta Buys It

Qualcomm Lays Out New Data Center Roadmap For AI; Meta Buys It

25 June 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » New Android Warning — This TOAD Malware Attack Steals Cash From ATMs
Innovation

New Android Warning — This TOAD Malware Attack Steals Cash From ATMs

Press RoomBy Press Room22 April 20253 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
New Android Warning — This TOAD Malware Attack Steals Cash From ATMs

Most Android malware is after one thing: your passwords. That’s just the way it is these days, with infostealer malware firmly at the top of the cyber attack tree. Some attacks can lead directly to attacks on your bank balance, as recently detailed in a new report warning of smartphone PIN code threats. Now, it would seem, one group of threat actors has moved things up a gear or two with a complex campaign involving Android malware, a telephone-oriented attack delivery methodology, and, ultimately, the theft of your cash from ATMs.Welcome to the weird and worrying world of SuperCard X TOAD attacks.

The Great Android ATM Heist

Threat intelligence experts Federico Valentini‍, Alessandro Strino and Michele Roviello, from fraud detection platform Cleafy, have reported how a “new and sophisticated Android malware campaign” called SuperCard X is intercepting and relaying near field communication messages from compromised devices to facilitate fraudulent ATM cash withdrawals. Yes, really. This malware can steal cash from ATMs.

“The innovative combination of malware and NFC relay empowers attackers to perform fraudulent cash-outs with debit and credit cards,” the researchers said, adding that it has demonstrated high success rates when targeting contactless ATM withdrawals.

The attack execution begins with, you guessed it, targeting social engineering tactics. The phishing messages, typically delivered by way of SMS or WhatsApp, use brand impersonation to leverage trust and add the necessary urgency to the fraud. By alerting victims to a suspicious outgoing payment, which is purported to be a bank fraud security alert, the user is prompted to call a support telephone number as a matter of some urgency. This is where the TOAD enters the equation. A telephone-oriented attack delivery allows the fraudsters to manipulate victims directly during phone conversations.

In the case of SuperCard X attacks, that manipulation flows as follows:

  • The victim is directed to reset their payment card PIN code.
  • They are then instructed to remove existing spending limits.
  • Then, a malicious app, disguised as a verification tool, must be installed, and this is where the SuperCard X malware with NFC-relay functionality arrives.
  • Finally, the victim has to take their physical payment card into proximity of their now-infected Android device, where the card details are silently captured.

The clever bit, assuming all of that social engineering has been successful, is that those card details are relayed in real-time to a second, attacker-controlled Android phone, used to make the contactless ATM withdrawals.

Security Expert Comments On SuperCard X Android TOAD Attack

If this threat expands, Randolph Barr, chief information security officer at Cequence, told me, it will likely be due to users falling victim to social engineering and being convinced to disable built-in security protections. Obviously, that’s a massive red flag, as no legitimate organization would ever ask you to do such a thing. “This attack highlights the importance of understanding what an app does before installing or sideloading it,” Barr said while advising that Google Play offers protections against such malicious apps and should be used rather than introducing the risk of sideloading applications from other sources. “There are ways to recognize and prevent TOAD-style attacks,” Barr concluded, suggesting that validating the legitimacy of any such request before acting on it is a great starting point.

A Google spokesperson confirmed this advice in a statement: “Based on our current detection, no apps containing this malware are found on Google Play. Android users are automatically protected by Google Play Protect, which is on by default on Android devices with Google Play Services.”

android malware ATM Cash Hack Cleafy Google malware Payment Card Theft smartphone SuperCard X TOAD
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Interfaces Make Memories Useful, SNIA MRAM SIG And Everspin

Interfaces Make Memories Useful, SNIA MRAM SIG And Everspin

25 June 2026
Qualcomm Lays Out New Data Center Roadmap For AI; Meta Buys It

Qualcomm Lays Out New Data Center Roadmap For AI; Meta Buys It

25 June 2026
New 60-Million-Star View Of Milky Way Opens Window For Exoplanet Hunting

New 60-Million-Star View Of Milky Way Opens Window For Exoplanet Hunting

25 June 2026
Hints & Clues For Thursday, June 25 (Just Relax)

Hints & Clues For Thursday, June 25 (Just Relax)

24 June 2026
How To Install Apple’s New iOS 27 Beta Firmware On AirPods Pro 3 And AirPods Max 2

How To Install Apple’s New iOS 27 Beta Firmware On AirPods Pro 3 And AirPods Max 2

24 June 2026
HPE Updates Hardware, Private Cloud And Networking For Agentic AI Era

HPE Updates Hardware, Private Cloud And Networking For Agentic AI Era

24 June 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
New 60-Million-Star View Of Milky Way Opens Window For Exoplanet Hunting

New 60-Million-Star View Of Milky Way Opens Window For Exoplanet Hunting

25 June 20265 Views
Getting past the pilot: Why so many AI test projects have trouble scaling

Getting past the pilot: Why so many AI test projects have trouble scaling

25 June 20265 Views
Hints & Clues For Thursday, June 25 (Just Relax)

Hints & Clues For Thursday, June 25 (Just Relax)

24 June 20267 Views
1,000-year-old massive textile factory unearthed in Denmark—and it belonged to the Vikings

1,000-year-old massive textile factory unearthed in Denmark—and it belonged to the Vikings

24 June 20267 Views

Recent Posts

  • Interfaces Make Memories Useful, SNIA MRAM SIG And Everspin
  • Trump’s Iran war made the Senate symbolically vote to curb his war powers for the first time
  • Qualcomm Lays Out New Data Center Roadmap For AI; Meta Buys It
  • ‘Godmother of AI’ and others in tech push for “world models” over chatbots, draw investors
  • New 60-Million-Star View Of Milky Way Opens Window For Exoplanet Hunting

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Interfaces Make Memories Useful, SNIA MRAM SIG And Everspin

Interfaces Make Memories Useful, SNIA MRAM SIG And Everspin

25 June 2026
Trump’s Iran war made the Senate symbolically vote to curb his war powers for the first time

Trump’s Iran war made the Senate symbolically vote to curb his war powers for the first time

25 June 2026
Qualcomm Lays Out New Data Center Roadmap For AI; Meta Buys It

Qualcomm Lays Out New Data Center Roadmap For AI; Meta Buys It

25 June 2026
Most Popular
‘Godmother of AI’ and others in tech push for “world models” over chatbots, draw investors

‘Godmother of AI’ and others in tech push for “world models” over chatbots, draw investors

25 June 20263 Views
New 60-Million-Star View Of Milky Way Opens Window For Exoplanet Hunting

New 60-Million-Star View Of Milky Way Opens Window For Exoplanet Hunting

25 June 20265 Views
Getting past the pilot: Why so many AI test projects have trouble scaling

Getting past the pilot: Why so many AI test projects have trouble scaling

25 June 20265 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.