Opens in a new tab

What a Spanish Carding Tutorial Reveals About How Fraudsters Actually Think

October 01, 2026

By Assaf Morag, Cybersecurity Researcher

A 2,200-word tutorial titled “Complete Guide to Carding in Spain (2026)” appeared on the Carder Market forum in April 2026. It is exactly what it sounds like: a beginner’s playbook for credit card fraud targeting the Spanish market, complete with entry fees, expected returns, and step-by-step operational workflows (we are holding back specific names and techniques to execute attacks to prevent these from falling into those with malicious intentions). This guide reveals a fascinating connection between malware campaigns and the fraud opportunities they create for the cybercrime ecosystem

Key Takeaways About Spanish Carding

  • The tutorial frames early 2026 as a “perfect storm” for Spanish carding. The author argues that Devil NFC malware campaigns have overwhelmed banks, specific retailers have exploitable payment workflows, and the availability of cheap tooling has lowered entry barriers for beginner fraudsters.
  • Devil NFC campaigns are presented as the enabling factor. The guide describes three NFC-relay fraud campaigns targeting Santander Bank, CaixaBank, and Unicaja since January 2026, claiming that the resulting flood of fraudulent transactions has strained Spanish banks’ detection capacity.
  • The tutorial names specific banks, BIN ranges, and retailers as weak points. While these claims cannot be independently verified, they reveal which targets underground actors are actively studying and where they believe defenses are insufficient.
  • Android is identified as the dominant fraud platform. The guide highlights a social engineering technique targeting Android users in Spain.
  • The intelligence value lies in attacker perception, not factual accuracy. Even where claims are exaggerated or unverifiable, they reveal adversarial assumptions, operational priorities, and emerging fraud trends before they become visible through traditional monitoring.
Flare CTA Block Preview

Cyber Threat Intelligence

See Where Attackers Believe Your Defenses Are Weak

Underground operational tutorials reveal attacker perceptions, preferred targets, successful techniques, operational costs, and expected profits — often before those trends surface through traditional security monitoring. Flare continuously collects and indexes this content across dark web forums, illicit Telegram channels, and paste sites, giving your team the raw material to map adversary assumptions against your own telemetry and fraud investigations.

✓ Continuous collection of underground guides, tutorials, and operator discussions across languages and regions
✓ Early warning on emerging fraud trends and the targets adversaries are actively investing in
Start a Free Trial →

The Tutorial in Figures

Carding in Spain 2026

A threat actor published the tutorial “Complete Guide to Carding in Spain (2026)” on the Carder Market forum earlier this year. Spanning six sections and more than 2,200 words, the guide provides a rare glimpse into how aspiring threat actors are being introduced to the Spanish cybercrime ecosystem. While much of the content is aimed at beginners, it contains several noteworthy threat intelligence insights relevant to the Spanish market, including:

  • The Devil NFC campaign: Described by the author as nothing less than a “game changer,” the guide summarizes the wave of NFC-enabled fraud campaigns that began targeting Spain in early 2026.
  • Credit card fraud in Spain (2026): A conceptual introduction to the Spanish payment fraud landscape, including common fraud schemes and monetization paths.
  • Android-based payment fraud: An overview of how compromised Android devices are leveraged in modern fraud operations.
  • Fraud against Spanish retailers: Observations on the structure of Spanish e-commerce websites, payment workflows, and perceived weaknesses.
  • A step-by-step operational workflow for beginners: A structured roadmap with entry fees and projected gains designed to help newcomers understand the fraud ecosystem. We have intentionally omitted these details to avoid facilitating the replication or broader dissemination of fraudulent techniques.
  • Operational security (OPSEC): Recommendations intended to help cybercriminals reduce their exposure to law enforcement and fraud prevention controls.

Although much of the material simplifies complex fraud operations and occasionally exaggerates certain claims, the guide offers valuable insight into the narratives, techniques, and operational assumptions being shared within underground communities targeting Spain.

One of many tutorial available on the underground (Flare link to post, sign up for the free trial to access if you aren’t already a customer)

The Perfect Storm: Why Spain, Why Credit Cards, and Why Now?

The tutorial’s conclusion (which we present first because it frames the author’s entire argument) claims that now is the ideal moment to begin credit card fraud in Spain. The author depicts a perfect storm: banks preoccupied with malware campaigns, specific businesses with security weaknesses, and hardware and software that lower entry barriers for beginners.

Below we examine the tutorial’s main claims and assess their accuracy.

The Devil NFC Campaigns

The threat actor presented three Devil NFC campaigns in Spain since January 2026 (Santander Bank, CaixaBank, and Unicaja), while arguing that the resulting transaction volume has strained fraud detection capacity, a claim we could not independently verify. The author also claims that Spanish users are “conditioned” to automatically swipe their credit cards against their mobile phone and enter the bank PIN. In addition, the threat actor suggests it’s easier to purchase daily “fresh credit cards” from Spanish users or have access to campaign logs.

What is Devil NFC?

Screenshot of the DevilNFC admin panel

DevilNFC performs a real-time NFC relay attack using two Android phones. The victim is socially engineered into installing a fake banking or verification app, placing their payment card against the phone, and entering the card’s PIN. The malware reads the live NFC communication between the phone and card and forwards it over the internet to an accomplice’s device positioned at an ATM or payment terminal. That second phone emulates the victim’s card, relaying the terminal’s requests back to the real card and returning its valid cryptographic responses. This allows the criminal to complete a withdrawal or contactless transaction remotely without physically possessing or cloning the card. DevilNFC can also use Android’s Kiosk Mode to trap the victim inside the fraudulent interface while the relay takes place.

Based on our experience with similar operations, this operation may adhere to a well documented cybercrime-as-a-service model, where different actors specialize in distinct stages of the attack chain. Initial access operators distribute phishing lures and malware, while downstream fraudsters use the stolen card data and relayed NFC communications to conduct fraudulent transactions or monetize access through underground markets.

Following the tutorial publication we observed a slight increase in Devil NFC access (Flare link to post, sign up for the free trial to access if you aren’t already a customer)

Imbalanced 3DS 2.0 Enforcement

According to the threat actor, banks differ significantly in how strictly they enforce 3D Secure (3DS) authentication, with several institutions maintaining strong controls while relying on frictionless authentication flows with less 3D Secure enforcement.

What is 3d Secure 2.0?

3D Secure 2.0 (3DS 2.0) is the modern authentication framework used by payment providers to reduce online credit card fraud. Unlike earlier versions that relied heavily on passwords and one-time codes, 3DS 2.0 uses risk-based analysis to evaluate each transaction in real time. Factors such as the user’s device, location, purchasing behavior, transaction amount, and merchant reputation are analyzed to determine whether a payment appears legitimate. Low-risk transactions can be approved seamlessly without interrupting the customer, while higher-risk purchases may trigger additional verification steps such as biometric authentication, banking app approval, or one-time passcodes.

From a security perspective, 3DS 2.0 significantly raises the barrier for attackers attempting to monetize stolen payment card data. Possessing a card number, expiration date, and CVV is often no longer sufficient to complete a fraudulent transaction. Instead, attackers must also bypass the issuing bank’s risk engine and authentication controls. This shift from simple card validation to behavioral and contextual verification has made large-scale payment fraud considerably more difficult, while simultaneously improving the user experience for legitimate customers by reducing unnecessary authentication challenges.

In this case, the tutorial reflects the threat actor’s perceptions and operational experiences rather than openly disclosed bank data, which is how the tutorial can help beginners in the underground. This is precisely what makes such content valuable as threat intelligence. Banks and financial institutions can ingest these claims, cross-validate them against internal fraud telemetry, and modify detection and prevention mechanisms accordingly. If attackers believe certain flows are weaker, defenders should verify whether that belief is grounded in reality.

We observed thousands of discussions about 3DS 2.0 implementation maturity (Flare link to post, sign up for the free trial to access if you aren’t already a customer)

Android as the Weapon of Choice

The guide highlights Android as the preferred platform for mobile banking malware and payment fraud because of its flexibility and comparatively broad access to device functionality. Features such as application sideloading, SMS access, accessibility services, browser customization, and NFC capabilities can be abused to steal credentials, intercept authentication codes, manipulate banking sessions, and facilitate contactless-payment fraud. Although these features support legitimate use cases, they also give cybercriminals many of the components needed to conduct large-scale banking-fraud campaigns, making Android the dominant platform in today’s mobile cybercrime ecosystem.

This assessment is broadly accurate, although iOS does not completely prevent NFC-relay attacks. Since iOS 17.4, Apple has supported entitlement-controlled Host Card Emulation for eligible applications in the European Economic Area, while later NFC and Secure Element APIs have expanded third-party contactless capabilities. EU users can also install applications through alternative marketplaces. However, Apple still places substantial entitlement, notarization, distribution, and review requirements around these capabilities. These controls make it considerably more difficult for criminals to distribute an iOS application capable of supporting the emulation side of an NFC relay, but they do not make the attack class technically impossible.

Android therefore remains the more practical target. Its less restrictive application-distribution model, mature NFC and Host Card Emulation capabilities, and greater exposure to applications installed from links or unofficial sources lower the operational barrier for attackers. The potential target population is also large: StatCounter measured Android at 68.64% of Spain’s mobile operating-system usage in August 2026. Combined with the established use of SMS messages to distribute fraudulent “security” or banking applications, this makes Android the platform of choice for campaigns such as DevilNFC, without implying that comparable abuse is categorically impossible on iOS.

Specific Targeted Businesses Across Spain

The threat actor names specific BIN ranges and businesses in Spain that are more susceptible to credit card fraud. The guide identifies particular BIN series numbers and transaction values that were purportedly successful. They appear to be based on the threat actor’s personal experience, suggesting that they conducted several successful fraudulent transactions before writing the guide. We found no public reporting confirming that these specific businesses or techniques are currently being exploited. The claims are either fabricated/exaggerated to increase the tutorial’s perceived value, or they represent genuine operational intelligence that could help those businesses close gaps.

Specific Ways to Avoid Detection

The guide includes two specific techniques that are presented as “a known workaround for some Spanish payment gateways.” While there’s no independent verification that these techniques work, they can provide invaluable insights for defenders on how attackers in Spain perceive their defense posture. The threat actor explains how a specific sequence of actions can possibly avoid triggering a 3DS challenge. We have reviewed the sequence, and decided not to publish it here.

Intelligence Value: Reading Between the Lines

While these observations provide insight into how underground threat actors perceive the Spanish payment ecosystem, several of the claims should be treated with caution. Banks do not publicly disclose the exact criteria used to trigger 3DS authentication challenges, and authentication decisions typically depend on a wide range of factors, including merchant risk, transaction value, device reputation, PSD2 exemptions, and issuer-specific risk models. In addition, some of the security flaws attributed to specific banks and businesses are more accurately described as ecosystem-wide attack techniques rather than weaknesses unique to a particular institution.

Overall, the data appears to reflect the author’s perceptions and operational experiences rather than independently verified measurements of banking security. What matters is what they reveal about:

  • Attacker perception: Where do fraudsters believe defenses are weak?
  • Operational priorities: Where are they investing time and resources?
  • Emerging trends: What campaigns and techniques are being promoted to newcomers?
  • Targeting decisions: Which institutions, BIN ranges, and merchant types are attracting attention?

Even inaccurate claims serve as early warning indicators of where adversaries intend to focus future attacks.

Recommendations For Defenders

For Spanish Financial Institutions

The tutorial demonstrates that threat actors are actively studying and sharing observations about Spanish banks, payment flows, and authentication mechanisms. Financial institutions should treat these observations as adversarial intelligence and validate them against their own fraud telemetry. If threat actors believe certain customer segments, BIN ranges, or transaction patterns receive fewer 3DS challenges, those assumptions should be tested and continuously reviewed.

Banks could also prioritize controls against Android-based malware campaigns such as Devil NFC. The combination of phishing, SMS lures, fake banking applications, credential theft, and NFC relay attacks creates a complete fraud chain that bypasses traditional card-theft models. Device enrollment, wallet provisioning, and high-risk transactions originating from newly registered devices should require additional verification, especially when preceded by recent credential resets, PIN changes, or suspicious customer interactions.

Having said that, DevilNFC is a live relay attack, not card cloning or replay. Victims are instructed to place their physical card against the phone, allowing the malware to relay transactions from a criminal’s ATM or payment terminal to the genuine card in real time. Banks should therefore warn customers that they will never ask them to tap a payment card against a phone for verification, fraud cancellation, or security updates.

Finally, institutions should actively monitor underground forums and fraud communities for discussions about their brand, authentication processes, BIN ranges, and transaction workflows. Even when the information is inaccurate, it reveals how attackers perceive defensive controls and where they intend to focus future attacks.

For Spanish Retailers and E-Commerce Platforms

The guide repeatedly references specific merchant workflows, transaction values, and purchasing patterns that fraudsters believe can be abused. Retailers should review online payment flows for opportunities where stolen cards can be tested with low-value purchases before being used for larger transactions.

Organizations offering click-and-collect, same-day pickup, gift cards, digital goods, or easily resold products should reassess their verification procedures. The guide specifically encourages threat actors to target businesses where payment authorization and product collection are loosely connected, reducing the need for identity verification after payment approval.

Retailers should also share fraud intelligence with acquiring banks and payment providers. If multiple organizations observe the same BIN ranges, device fingerprints, or transaction patterns discussed in underground communities, coordinated action can significantly reduce the effectiveness of these fraud playbooks.

For Threat Intelligence and Security Teams

This guide illustrates why underground operational tutorials should be treated as valuable threat intelligence rather than dismissed as low-quality criminal content. While many claims are exaggerated or unverifiable, the document reveals attacker perceptions, preferred targets, successful techniques, operational costs, and expected profits. Though this guide focuses on Spain, security teams across the EMEA region and globally can learn from it.

Security teams can continuously map these attacker assumptions against internal telemetry, fraud investigations, and incident response data. The objective is not to determine whether every claim is correct, but to identify where adversaries believe defenses are weak and where they are investing time and resources. In many cases, these perceptions provide an early warning of emerging fraud trends before they become visible through traditional security monitoring.

What a Beginner Threat Actor’s Tutorial Can Provide for Threat Intelligence

A 2,200-word beginner’s guide to carding in Spain is not at face-value a sophisticated piece of threat intelligence. But that is exactly what makes it valuable. The tutorial reveals what experienced threat actors believe works, which institutions they consider vulnerable, which campaigns they view as enabling factors, and how they advise newcomers to allocate limited resources. These are targeting decisions made explicit.

Where the tutorial’s claims align with real gaps, the priority is obvious. Where they do not, defenders gain something equally useful: insight into where attackers will waste their time. Either way, dismissing underground educational material because it is aimed at beginners misses the point. Beginners follow instructions. When those instructions name your institution, your BIN ranges, and your payment workflows, the volume of attempts that follows is not beginner-level at all.

Flare CTA Block Preview

Cyber Threat Intelligence

See Where Attackers Believe Your Defenses Are Weak

Underground operational tutorials reveal attacker perceptions, preferred targets, successful techniques, operational costs, and expected profits — often before those trends surface through traditional security monitoring. Flare continuously collects and indexes this content across dark web forums, illicit Telegram channels, and paste sites, giving your team the raw material to map adversary assumptions against your own telemetry and fraud investigations.

✓ Continuous collection of underground guides, tutorials, and operator discussions across languages and regions
✓ Early warning on emerging fraud trends and the targets adversaries are actively investing in
Start a Free Trial →
Share article