Ghost-tapping and the Chinese cybercriminal retail fraud ecosystem
Ghost-tapping is a relatively new and popular attack vector used mainly by Chinese-speaking threat actors who use Near Field Communication (NFC) relay tactics to commit retail fraud by using stolen payment card details linked to mobile payment services (such as Apple Pay and Google Pay).
This technique allows these threat actors to provide mules with stolen payment card details linked to contactless payment systems in person to obtain physical goods, eventually transporting and reselling stolen goods for profit. Insikt Group analysts identified a key threat actor on Telegram, @webu8, advertising burner phones and ghost-tapping services to Chinese-speaking threat groups (referred to as syndicates) and engaged with threat actors involved in retail fraud campaigns.
Even though Huione Guarantee, a Telegram-based criminal marketplace, announced it shut down its operations on May 13, 2025, we observed cybercriminals and syndicates have since been using Huione Guarantee’s existing massive decentralized infrastructure on Telegram to conduct dealings. Chinese-speaking cybercriminals have also pivoted to Xinbi Guarantee and Tudou Guarantee platforms as one-stop shops to recruit ghost-tapping, transportation, reseller and money laundering mules.
Read more at Recorded Future