Skip to content

ESET 透過投資加速 AI 創新,以因應快速擴大的攻擊面

布拉提斯拉瓦2026 年 5 月 19 日 — 全球網路安全領導廠商及人工智慧領域的長期先驅 ESET 今日宣布,已正式加入 代理型 AI 基金會(Agentic AI Foundation, AAIF) 成為銀級會員*,進一步強化其致力於打造安全、以人為本之代理型 AI 的承諾。透過此會員身分,ESET 將以獨立且研究驅動的網路安全專業知識,為推動 AI 代理(AI agents)的開放協定、跨平台相容性以及商用級標準的全球努力做出貢獻。

AAIF 是在 Linux 基金會(Linux Foundation)主持下成立的中立、開放基金會,旨在建構開放標準的代理型 AI 技術堆疊。隨著代理型 AI 從實驗階段邁向實際部署,該基金會迅速擴大的會員陣容,突顯了業界對推動共享標準的強大動能。

「代理型 AI 正成為新型的數位防護邊界。塑造它需要明確的目標、嚴謹的工程技術,以及安全優先的方法。對我們而言,這是數十年來工作成果的自然延伸——我們開發的 AI 凌駕於短期趨勢之上,並深植於誠信與社會影響力,」ESET 人工智慧副總裁 Juraj Janošík 表示。

藉由加入 AAIF,ESET 強化了其長期以來對負責任意義創新和「內建安全(Security-by-design)」的專注,支持開發可安全進行規模化部署的開放式代理型 AI 系統。作為代理型 AI 基金會中專注於網路安全的成員,ESET 將與 OpenAI、Anthropic、亞馬遜(Amazon)、微軟(Microsoft)等業界巨頭攜手合作,共同建立受信任的標準以及確保 AI 代理互通性(Interoperability)的安全協定。

了解更多關於 ESET 倫理 AI 使用 的詳細資訊。

* 由於代理型 AI 基金會隸屬於 Linux 基金會,ESET 將自動成為 Linux 基金會生態系統的一部分。

 

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET 透過 ESET PRIVATE 在全球加倍投入客製化解決方案

  • 基於多年為具備複雜資安需求之機構服務的深厚經驗,ESET 今日將其全球客製化服務正式升級為 ESET PRIVATE。
  • ESET PRIVATE 旨在為大型企業和公共部門環境提供量身打造的客製化解決方案,實現規模化的網路韌性。
  • 該解決方案陣容涵蓋高速威脅掃描、完全實體隔離(Air-gapped)環境資安、IT 與 OT 基礎設施防護、專屬威脅情資以及複雜的託管安全服務(MSS)。
  • 在德國柏林舉辦的 ESET World 2026 大會上,與會者將能深入了解這一系列客製化解決方案所帶來的強大優勢。

布拉提斯拉瓦、柏林2026 年 5 月 18 日 — 全歐最大網路安全廠商* ESET 今日宣布,將於 ESET World 2026 全球大會上首度亮相其 ESET PRIVATE 產品組合。

大型組織的基礎設施日益複雜,且面臨著嚴格的合規要求與不斷攀升的威脅。對他們而言,標準化的罐頭產品已不敷使用。為了確保營運不中斷,組織亟需一套能與其基礎設施無縫融合的客製化資安防護。

為了解決此痛點,ESET PRIVATE 專為複雜的企業與公共部門環境而設計,提供以諮詢為導向的客製化網路安全服務。其服務對象涵蓋全球龍頭企業、國防組織、關鍵基礎設施營運商以及政府機構等,能靈活適應各種嚴苛的要求與營運環境——即便面對極度重視數據在地化(Data Residency)與數位主權的環境亦然。

「作為標準 B2B 與企業產品組合的延伸,ESET PRIVATE 解決方案旨在滿足大型企業和政府機構的特定需求與情境,」ESET 通路營運與業務擴張副總裁 David Března 表示。「各個產業的客戶如今正從『購買技術』轉向『管理網路風險』,同時他們還必須應對瞬息萬變的地緣政治、數位架構以及工具與數據過載的挑戰。ESET 的角色正從傳統的技術供應商演變為戰略夥伴,我們交付的是契合每個組織業務、營運及法規情境的專屬資安解決方案。
因此,無論您是希望保護客戶免受釣魚詐騙的銀行、需要捍衛關鍵傳統 OT 技術的老牌製造商、亟需威脅情資來守護輸配電網的能源公司,還是追求超越單純數據儲存主權的政府機構,ESET 都能提供遠超乎大眾過去所熟知的強大能量。」

ESET PRIVATE(前身為 Corporate Solutions 企業解決方案)交付以下核心價值

  • 客製化設計與建構:ESET 專屬的工程師與架構師團隊與客戶緊密合作,調整、實施並擴展解決方案,以滿足其高階防護與營運需求。
  • 模組化解決方案組合:客戶可根據自身需求,自由搭配與組合任何 ESET PRIVATE 的方案。
  • 雲端或地端解決方案:提供彈性的部署選項,與客戶複雜的基礎設施和業務運作進行無縫整合。
  • 顧問諮詢式方法:ESET 基於深厚的產業知識,提供專家級的戰略建議。
  • 端到端(End-to-End)解決方案:ESET 提供長期的合作夥伴關係,並涵蓋持續性的解決方案生命週期管理。

憑藉超過 30 年的網路安全經驗與全球威脅情資,ESET PRIVATE 將 ESET 屢獲殊榮的產品與獨家核心技術、專家團隊相結合,提供強韌的數位安全與客製化解決方案。ESET 的多層次安全解決方案融合了 AI 力量與專家經驗,協助企業超越基礎的合規要求,並全面支援雲端及地端(On-premises)環境。

在 ESET World 2026 掌握更多資訊

ESET 將在其年度 ESET World 大會上向公眾展示 ESET PRIVATE。本屆大會匯聚了來自全球的網路安全專家,共同見證、體驗並探討 ESET PRIVATE 及其卓越的解決方案與服務,提供第一手的專業視角。

在眾多精采演講中,將有數場專門針對「高壓、高風險環境」的專題探討,由 ESET 頂尖專家主持並邀請業內享譽盛名的權威共同參與:

超越單一標準的安全:滿足高風險組織的獨特需求(Beyond One-Size-Fits-All Security: Meeting the Needs of High-Risk Organizations)
Juraj Malcho – ESET 科技長(CTO)
Martin Talian – ESET 企業解決方案長(Chief Corporate Solutions Officer)

隨著威脅的複雜度與破壞力與日俱增,標準化的通用防護已無法保護所有組織。某些組織運作於極度重視信任、韌性與自主控制權的環境中,需要截然不同的高階安全方法。

我們該如何保護在受限與自主環境中運行的系統?(How can we secure systems operating in restricted and autonomous environments?)
Patrik Pliesovsky: ESET 交付與部署總監

保護在受限環境中運作的系統正面臨前所未有的挑戰,尤其是當具備自主能力的 AI 代理(Agents)演進到無需人類干預即可獨立做出決策時。本專題將探討在設計適用於受限與自主系統之網路安全架構時的關鍵考量,並聚焦於如何在營運自主性與強韌的安全控制之間取得平衡——確保系統在孤立、資源受限或實體隔離(Air-gapped)的環境中,依舊能體現系統完整性、持續性行為監控與卓越的韌性。

數位前線的網路防禦(Cyber Defense at the Digital Front lines)
Andrew Lee,ESET 政府事務副總裁
Mietta Groeneveld 上校,北約(NATO)指揮與控制卓越中心總監
Hans De Vries,歐盟網路安全局(ENISA)網路安全與營運長

本論壇匯集了高階資安專家,共同探討日益加劇的國家級網路侵略行為。這些敵對政權正逐漸忽視國際網路規範,頻繁進行間諜活動並攻擊關鍵基礎設施。隨著敵對勢力利用數位技術、發動具破壞力的網路攻擊,並開始槓桿 AI 技術,防禦者在捍衛公民自由與保護國民的同時,正面臨反制這場不對稱戰爭的複雜挑戰。

論壇將深入探討韌性戰略,檢視在持續衝突的時代下如何保護基本公共服務。最終,本場專題將解答防禦者如何在不犧牲自身極力守護的核心價值之前提下,穩固其數位前線。

戰略網路韌性:對抗國家級戰爭的新前線(Strategic Cyber Resilience: The New Front Line Against Nation-State Warfare,爐邊談話)
Thomas Hemker – Guter Hafen Cyber-Sicherheit 安全科技長兼網路風險顧問
Mietta Groeneveld 上校,北約(NATO)指揮與控制卓越中心總監

隨著國家級行動者模糊了網路戰與網路犯罪之間的界線,採用精密的 AI 驅動戰術瞄準供應鏈與關鍵基礎設施,傳統以防禦為導向的安全模型已相形見絀。業界對先進、具備韌性的安全架構之需求從未如此迫切。本論壇將討論如何將「網路韌性」視為現代國防戰略的基石,將網路安全從成本中心轉化為競爭優勢。

請前往線上註冊並觀看本屆於德國柏林 JW 萬豪酒店舉行的盛大年會(活動時間為 5 月 19̶20 日)。

*根據 Frost Radar™: Endpoint Security, 2025 (Frost & Sullivan) 報告評選,ESET 為全歐洲最大的網路安全供應商。

了解更多關於 ESET PRIVATE 的詳細資訊。

閱讀更多關於 ESET PRIVATE 工業安全如何解決製造業傳統運作技術(OT)安全痛點的專題文章。

 

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET 透過 ESET PRIVATE 在全球加倍投入客製化解決方案

  • 基於多年為具備複雜資安需求之機構服務的深厚經驗,ESET 今日將其全球客製化服務正式升級為 ESET PRIVATE。
  • ESET PRIVATE 旨在為大型企業和公共部門環境提供量身打造的客製化解決方案,實現規模化的網路韌性。
  • 該解決方案陣容涵蓋高速威脅掃描、完全實體隔離(Air-gapped)環境資安、IT 與 OT 基礎設施防護、專屬威脅情資以及複雜的託管安全服務(MSS)。
  • 在德國柏林舉辦的 ESET World 2026 大會上,與會者將能深入了解這一系列客製化解決方案所帶來的強大優勢。

布拉提斯拉瓦、柏林2026 年 5 月 18 日 — 全歐最大網路安全廠商* ESET 今日宣布,將於 ESET World 2026 全球大會上首度亮相其 ESET PRIVATE 產品組合.

大型組織的基礎設施日益複雜,且面臨著嚴格的合規要求與不斷攀升的威脅。對他們而言,標準化的罐頭產品已不敷使用。為了確保營運不中斷,組織亟需一套能與其基礎設施無縫融合的客製化資安防護。

為了解決此痛點,ESET PRIVATE 專為複雜的企業與公共部門環境而設計,提供以諮詢為導向的客製化網路安全服務。其服務對象涵蓋全球龍頭企業、國防組織、關鍵基礎設施營運商以及政府機構等,能靈活適應各種嚴苛的要求與營運環境——即便面對極度重視數據在地化(Data Residency)與數位主權的環境亦然。

「作為標準 B2B 與企業產品組合的延伸,ESET PRIVATE 解決方案旨在滿足大型企業和政府機構的特定需求與情境,」ESET 通路營運與業務擴張副總裁 David Března 表示。「各個產業的客戶如今正從『購買技術』轉向『管理網路風險』,同時他們還必須應對瞬息萬變的地緣政治、數位架構以及工具與數據過載的挑戰。ESET 的角色正從傳統的技術供應商演變為戰略夥伴,我們交付的是契合每個組織業務、營運及法規情境的專屬資安解決方案。
因此,無論您是希望保護客戶免受釣魚詐騙的銀行、需要捍衛關鍵傳統 OT 技術的老牌製造商、亟需威脅情資來守護輸配電網的能源公司,還是追求超越單純數據儲存主權的政府機構,ESET 都能提供遠超乎大眾過去所熟知的強大能量。」

ESET PRIVATE(前身為 Corporate Solutions 企業解決方案)交付以下核心價值

  • 客製化設計與建構:ESET 專屬的工程師與架構師團隊與客戶緊密合作,調整、實施並擴展解決方案,以滿足其高階防護與營運需求。
  • 模組化解決方案組合:客戶可根據自身需求,自由搭配與組合任何 ESET PRIVATE 的方案。
  • 雲端或地端解決方案:提供彈性的部署選項,與客戶複雜的基礎設施和業務運作進行無縫整合。
  • 顧問諮詢式方法:ESET 基於深厚的產業知識,提供專家級的戰略建議。
  • 端到端(End-to-End)解決方案:ESET 提供長期的合作夥伴關係,並涵蓋持續性的解決方案生命週期管理。

憑藉超過 30 年的網路安全經驗與全球威脅情資,ESET PRIVATE 將 ESET 屢獲殊榮的產品與獨家核心技術、專家團隊相結合,提供強韌的數位安全與客製化解決方案。ESET 的多層次安全解決方案融合了 AI 力量與專家經驗,協助企業超越基礎的合規要求,並全面支援雲端及地端(On-premises)環境。

在 ESET World 2026 掌握更多資訊

ESET 將在其年度 ESET World 大會上向公眾展示 ESET PRIVATE。本屆大會匯聚了來自全球的網路安全專家,共同見證、體驗並探討 ESET PRIVATE 及其卓越的解決方案與服務,提供第一手的專業視角。

在眾多精采演講中,將有數場專門針對「高壓、高風險環境」的專題探討,由 ESET 頂尖專家主持並邀請業內享譽盛名的權威共同參與:

超越單一標準的安全:滿足高風險組織的獨特需求(Beyond One-Size-Fits-All Security: Meeting the Needs of High-Risk Organizations)
Juraj Malcho – ESET 科技長(CTO)
Martin Talian – ESET 企業解決方案長(Chief Corporate Solutions Officer)

隨著威脅的複雜度與破壞力與日俱增,標準化的通用防護已無法保護所有組織。某些組織運作於極度重視信任、韌性與自主控制權的環境中,需要截然不同的高階安全方法。

我們該如何保護在受限與自主環境中運行的系統?(How can we secure systems operating in restricted and autonomous environments?)
Patrik Pliesovsky: ESET 交付與部署總監

保護在受限環境中運作的系統正面臨前所未有的挑戰,尤其是當具備自主能力的 AI 代理(Agents)演進到無需人類干預即可獨立做出決策時。本專題將探討在設計適用於受限與自主系統之網路安全架構時的關鍵考量,並聚焦於如何在營運自主性與強韌的安全控制之間取得平衡——確保系統在孤立、資源受限或實體隔離(Air-gapped)的環境中,依體現系統完整性、持續性行為監控與卓越的韌性。

數位前線的網路防禦(Cyber Defense at the Digital Front lines)
Andrew Lee,ESET 政府事務副總裁
Mietta Groeneveld 上校,北約(NATO)指揮與控制卓越中心總監
Hans De Vries,歐盟網路安全局(ENISA)網路安全與營運長

本論壇匯集了高階資安專家,共同探討日益加劇的國家級網路侵略行為。這些敵對政權正逐漸忽視國際網路規範,頻繁進行間諜活動並攻擊關鍵基礎設施。隨著敵對勢力利用數位技術、發動具破壞力的網路攻擊,並開始槓桿 AI 技術,防禦者在捍衛公民自由與保護國民的同時,正面臨反制這場不對稱戰爭的複雜挑戰。

論壇將深入探討韌性戰略,檢視在持續衝突的時代下如何保護基本公共服務。最終,本場專題將解答防禦者如何在不犧牲自身極力守護的核心價值之前提下,穩固其數位前線。

戰略網路韌性:對抗國家級戰爭的新前線(Strategic Cyber Resilience: The New Front Line Against Nation-State Warfare,爐邊談話)
Thomas Hemker – Guter Hafen Cyber-Sicherheit 安全科技長兼網路風險顧問
Mietta Groeneveld 上校,北約(NATO)指揮與控制卓越中心總監

隨著國家級行動者模糊了網路戰與網路犯罪之間的界線,採用精密的 AI 驅動戰術瞄準供應鏈與關鍵基礎設施,傳統以防禦為導向的安全模型已相形見絀。業界對先進、具備韌性的安全架構之需求從未如此迫切。本論壇將討論如何將「網路韌性」視為現代國防戰略的基石,將網路安全從成本中心轉化為競爭優勢。

請前往線上註冊並觀看本屆於德國柏林 JW 萬豪酒店舉行的盛大年會(活動時間為 5 月 19̶20 日)。

*根據 Frost Radar™: Endpoint Security, 2025 (Frost & Sullivan) 報告評選,ESET 為全歐洲最大的網路安全供應商。

了解更多關於 ESET PRIVATE 的詳細資訊。

閱讀更多關於 ESET PRIVATE 工業安全如何解決製造業傳統運作技術(OT)安全痛點的專題文章。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET Research uncovers CallPhantom scam on Google Play: Fake logs for real money

  • A new Android scam, CallPhantom, falsely claims to provide access to call logs, SMS records, and WhatsApp call history for any phone number in exchange for payment.
  • We identified and reported 28 separate CallPhantom apps on Google Play, cumulatively downloaded more than 7.3 million times.
  • Some CallPhantom apps sidestep Google Play’s official billing system, complicating victims’ refund efforts.

BRATISLAVA, KOŠICEMay 7, 2026 — ESET researchers have uncovered fraudulent apps on Google Play that claim to provide the call history “for any number.” The offending apps, which ESET named CallPhantom based on their false claims, purport to provide access to call histories, SMS records, and even WhatsApp call logs for any phone number. To unlock this supposed feature, users are asked to pay — but all they get in return is randomly generated data. ESET’s investigation identified 28 such fraudulent apps, cumulatively downloaded more than 7.3 million times. As an App Defense Alliance partner, we reported our findings to Google, which removed all of the apps identified in this report from Google Play. 

The CallPhantom apps mainly targeted Android users in India and the broader Asia Pacific region. Many of the apps came with India’s +91 country code preselected, and support UPI, a payment system used primarily in India.

“In November 2025, we came across a Reddit post discussing an app named Call History of Any Number, found on Google Play. Unsurprisingly, our analysis showed that the ‘call history’ data provided by this app is entirely fabricated — the app generates random phone numbers and matches them with fixed names, call times, and call durations, which were embedded directly in the code,” says ESET researcher Lukáš Štefanko, who uncovered the CallPhantom fraud.

In general, CallPhantom apps have a simple user interface and do not request any intrusive or sensitive permissions — they don’t need to. Coincidentally, they do not contain any functionality capable of retrieving actual call, SMS, or WhatsApp data.
In the CallPhantom apps ESET analyzed, researchers saw three different payment methods used, two of which are in violation of Google Play’s payments policy. Some of the apps relied on subscriptions via Google Play’s official billing system. Others relied on payments via a third party; in some cases, payment card checkout forms were included directly in the CallPhantom apps.

The fees requested for the fake service differ widely across the apps. The apps also appear to offer different subscription packages, such as weekly, monthly, or yearly services, with the highest requested price sitting at US$80. For the lowest “subscription tier,” the average requested price was €5.

In general, subscriptions purchased through the official Google Play billing system can be canceled. For the 28 apps described in this blog post, existing subscriptions were canceled when the apps were removed from Google Play. In some cases, refunds for Google Play purchases are possible.

If the purchase was made outside of Google Play — for example, by entering payment card details inside the app or by paying via third-party services — then Google cannot cancel the subscription or issue a refund, and users have to contact their payment provider.

For a more details about CallPhantom, check out the latest ESET Research blog post, “Fake call logs, real payments: How CallPhantom tricks Android users,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Examples of CallPhantom apps found on Google Play

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET Research: New NGate hides in NFC payment app, possibly built with AI

  • ESET researchers discovered a new NGate malware variant abusing the legitimate Android HandyPay application.
  • To trojanize HandyPay, threat actors most likely used GenAI.
  • The campaign has been ongoing since November 2025 and targets Android users in Brazil.
  • ESET investigated two NGate samples being distributed in the attacks: one via a fake lottery website, the other through a fake Google Play website.

BRATISLAVAApril 21, 2026 — ESET Research has discovered a new variant of the NGate malware family that abuses a legitimate Android application called HandyPay, instead of the previously leveraged NFCGate tool. The threat actors took the app, which is used to relay NFC data, and patched it with malicious code that appears to have been AI generated. As with previous iterations of NGate, the malicious code allows the attackers to transfer NFC data from the victim’s payment card to their own device and use them for contactless ATM cash-outs and unauthorized payments. Additionally, the code can capture the victims’ payment card PINs and exfiltrate them to the operators’ C&C server. The primary targets of this are users in Brazil; however, NFC-based attacks are expanding into new regions.

The malicious code used to trojanize HandyPay shows signs of having been produced with the help of GenAI tools. Specifically, the malware logs contain an emoji typical of AI-generated text, suggesting that LLMs were involved in generating or modifying the code, although definitive proof remains elusive. This fits a broader trend in which GenAI lowers the barrier to entry for cybercriminals, enabling threat actors with limited technical skill to produce workable malware.

ESET Research believes that the campaign distributing the trojanized HandyPay began around November 2025 and remains active. It should also be noted that the maliciously patched version of HandyPay has never been available on the official Google Play store. As an App Defense Alliance partner, we shared our findings with Google. ESET also reached out to the HandyPay developers to alert them about the malicious use of their application.

As the number of NFC threats keeps rising, so too has the ecosystem supporting them become more robust. The first NGate attacks employed the open-source NFCGate tool to facilitate the transfer of NFC data. Since then, several malware-as-a-service (MaaS) offerings with similar functionality have become available for purchase. However, in this campaign the threat actors decided to go with their own solution and maliciously patched an existing app – HandyPay.

“Why did the operators of this campaign decide to trojanize the HandyPay app instead of going with an established solution for relaying NFC data? The answer is simple: money. The subscription fees for existing MaaS kits run in the hundreds of dollars: NFU Pay advertises its product for almost US$400 per month, while TX-NFC goes for around US$500 per month. On the other hand, the legitimate HandyPay app is significantly cheaper, only asking for a €9.99 per month donation, if even that. In addition to the price, HandyPay natively does not require any permissions, only to be made the default payment app, helping the threat actors avoid raising suspicion,” says ESET researcher Lukáš Štefanko, who discovered the new NGate variant in the trojanized NFC payment app.

The first new NGate sample is distributed through a website that impersonates Rio de Prêmios, a lottery run by the Rio de Janeiro state lottery organization (Loterj). The second NGate sample is distributed via a fake Google Play web page as an app named Proteção Cartão (machine translation: Card Protection). Both sites were hosted on the same domain, strongly implying a single threat actor. The malware abuses the HandyPay service to forward NFC card data to an attacker-controlled device. Apart from relaying NFC data, the malicious code also steals payment card PINs, enabling the threat actor to use the victim’s payment card data to withdraw cash from ATMs.

For a more detailed analysis of the new NGate variant, check out the latest ESET Research blog post, “New NGate variant hides in a trojanized NFC payment app,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Geographical distribution of NGate attacks from January 2025 to February 2026

 

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×