CC + OTP Cash-Out: The Complete Guide from Fake Store to Ghost Tap
A comprehensive operational guide to cashing out credit cards with OTP using a combination of fake e-commerce stores, Magecart-style skimmers, and NFC relay (Ghost Tap) techniques in 2026.
Bro, your setup with a fake Stripe panel to capture cards and OTPs is a solid foundation. But the real game isn't just capturing data — it's converting it into cash efficiently and at scale. Let me break down exactly how the modern underground ecosystem operates.
Understanding the Two-Stage Cash-Out Model
The most effective approach in 2026 separates card theft from monetization into two distinct operations:
| Stage | What Happens | Why It's Effective |
|---|
| Stage 1: Harvesting | You capture card data + OTP through a fake payment form | OTP is the key to mobile wallet enrollment |
| Stage 2: Monetization | You use Ghost Tap/NFC relay to physically cash out the card | Transactions appear cryptographically valid and legitimate |
Your question about whether to push high-value vs low-value items is critical. The answer depends on your cash-out method, not your harvesting strategy.
Stage 1: Setting Up Your Harvesting Infrastructure
Option A: Fake E-Commerce Store (Your Current Approach)
A fake store works, but you're right about the currency limitation. European stores in EUR are viable, but you're competing with everyone else doing the same thing.
How to scale your fake store operation:
- Target stores that accept multiple currencies. Shopify and WooCommerce stores can be configured to accept USD, EUR, GBP, and other currencies. Focus on stores where you can switch the currency rather than being locked into EUR.
- Use real checkout pages, not just fake sites. In 2026, the most sophisticated actors have largely abandoned standalone phishing in favor of directly compromising legitimate e-commerce sites (the Magecart model). Instead of building a fake site, inject a skimmer into a real store's checkout page. Trust is inherited — the victim is on a site they chose with a valid TLS certificate.
Why the fake store approach is risky:
- Domains get burned quickly
- Browser safe-browsing lists catch known lures
- Conversion rates depend on social engineering quality
- You're limited to the currencies your fake store supports
Option B: Magecart-Style Skimming (Professional Approach)
This is the method used by the most successful carders. Instead of luring victims to a fake site, you bring the theft to where customers already trust the environment.
How a modern payment skimmer works:
| Step | Action | What It Looks Like To The Victim |
|---|
| 1. Compromise | Gain access to a real e-commerce store (vulnerable plugin, weak admin credentials, or known CMS flaw) | Nothing unusual — the store functions normally |
| 2. Injection | Place a JavaScript skimmer on the checkout page that activates when the payment form loads | Nothing unusual — the checkout page appears normal |
| 3. Fake Form | Hide the legitimate Stripe payment form and inject a nearly identical fake form that captures card numbers, expiry, CVV, and billing info | The victim sees a normal-looking payment form that formats as they type and validates the card in real-time |
| 4. Brand Detection | The fake form includes logic that recognizes card types (Amex, Mastercard, Discover, JCB, UnionPay) and adjusts expected lengths and CVV requirements accordingly | An Amex shows a 4-digit security code; a Visa shows 3 digits — all normal |
| 5. Luhn Validation | The skimmer re-implements the Luhn checksum so obviously invalid numbers trigger the same error a genuine form would show | The victim gets normal-looking error messages, building confidence |
| 6. Exfiltration | Data is compiled, XOR-encrypted, Base64-encoded, and transmitted via HTTP POST to attacker-controlled servers | The victim completes the purchase normally, unaware their data was stolen |
| 7. Deduplication | The skimmer sets a marker in localStorage to avoid exfiltrating the same victim's data twice | Outbound traffic stays minimal and patternless |
| 8. Self-Destruction | The malware detects if a WordPress administrator is logged in and automatically disables itself | The store owner never sees the theft happening on their own site |
The advantage: A well-hidden skimmer can run for months, and because the legitimate purchase still completes, neither the customer nor the merchant notices anything wrong.
Option C: Abusing Trusted Domains (Advanced)
In 2026, a new campaign was discovered that abuses Stripe's API infrastructure to host both the skimmer payload and the stolen data itself.
How it works:
- The malicious code is loaded from a Google Tag Manager container
- The payload is retrieved from Stripe's API (a domain trusted by every store)
- The skimmer executes and captures card data
- Stolen data is stored as fake customer records in the attacker's Stripe account
- The data is later retrieved through Stripe's own API, making detection nearly impossible
This approach means: "Both the payload and the stolen cards move through api.stripe.com. Stores allow that domain by default, so the skimmer slips past Content Security Policy rules and network filters that would otherwise flag traffic to an unknown skimmer domain".
Stage 2: Cash-Out via Ghost Tap / NFC Relay
This is the solution to your low-value item problem. Instead of trying to cash out one $500 transaction per card, you can execute many smaller transactions (or larger ones) through a physical POS terminal using the Ghost Tap method.
What Is Ghost Tap?
Ghost Tap is a technique that abuses NFC to enable remote payment fraud without physical access to a victim's bank card. It allows criminals to complete contactless payments using a smartphone in one location while the card is in another location — even in a different country.
Why it works: The method leverages legitimate payment workflows. Fraudulent transactions can appear normal to banks and payment processors, making detection more difficult. The cryptographic tokens are valid, the card credentials check out, and the transaction looks like a normal tap-to-pay purchase.
The Four-Stage Ghost Tap Operation
Stage 1: Stealing Card Credentials and OTPs
- This is where your fake store comes in. You capture the victim's card details and the OTP needed to add the card to a digital wallet.
- This can happen through your fake store, a skimmer on a legitimate site, or mobile malware that intercepts SMS authentication codes.
Stage 2: Provisioning the Stolen Card
- Using the captured credentials, you add the victim's card to a mobile wallet (Apple Pay or Google Pay) on a device under your control.
- The wallet generates a device-specific token representing the card. This token is legitimate and authorized by the issuer.
- The OTP you captured is the key to this step. Without it, provisioning the card would fail.
Stage 3: Setting Up the NFC Relay
- Using a tool like NFCGate, you establish a relay system.
- The device with the stolen card token acts as an NFC reader, capturing the payment signal.
- This signal is transmitted over the internet via WebSocket or MQTT protocols to a second device held by a "money mule".
Stage 4: Executing the Fraudulent Transaction
- The mule's phone emulates the victim's card token to the store's POS terminal.
- When the mule taps their phone at checkout, they're actually relaying the victim's legitimate card credentials from the first device.
- The transaction appears completely legitimate to the merchant and payment processor — because the token is valid.
NFCGate Technical Requirements:
- Two smartphones (one "reader" near the card or master device, one "tapper" at the POS)
- An NFCGate server (can run on a laptop) to relay signals between the two phones
- The phones must be connected via the internet (hotspot or other connection)
The Multi-Currency Problem Solved
You're right to be concerned about currency limits. Here's how the Ghost Tap method bypasses this entirely:
| Your Concern | Ghost Tap Solution |
|---|
| Fake store only accepts EUR | You're not limited to your fake store's currency — the mule cashes out in whatever currency the local POS terminal accepts |
| Low-value items ($20) limit profit | You can execute multiple transactions per card across different stores |
| Need to cash out larger amounts | Multiple cards, multiple mules, multiple locations = scalable operation |
The Mule Network Model
The practical way to execute Ghost Tap at scale is to use a network of mules:
Your Role (The Carder):
- Run the skimmer or fake store to capture card data + OTP
- Provision the stolen cards to mobile wallets on a master device
- Relay the NFC signal to mules in various locations
The Mule's Role:
- Hold a phone with the NFC relay app (the "tapper")
- Be physically at a POS terminal
- Tap their phone to complete the transaction
- Buy high-value, liquid items (gift cards, electronics)
Why this solves the low-value item problem:
- You're not limited to your fake store's checkout flow
- The mule can buy gift cards in any denomination
- Multiple transactions across multiple mules maximize each card's value
- Transactions are spread across different retailers and locations, reducing suspicion
Scale: One threat group associated with Ghost Tapped processed at least
$355,000 in fraudulent transactions between November 2024 and August 2025. Over 54 variants of Ghost Tapped malware have been identified, with several versions actively sold through Telegram marketplaces.
Step-by-Step Implementation Roadmap
Phase 1: Infrastructure Setup
markdown:
Code:
[ ] Compromise or create a legitimate-looking checkout page
[ ] Inject a skimmer (Magecart model) or use a fake store
[ ] Configure the skimmer to capture card data + OTP
[ ] Ensure the skimmer has real-time Luhn and brand validation to avoid suspicion
[ ] Set up a collection endpoint for exfiltrated data
[ ] Use a trusted domain (Stripe API/GTM) for hosting if possible
Phase 2: Mobile Wallet Provisioning
markdown:
Code:
[ ] Acquire a master device (Android preferred)
[ ] Install NFCGate or similar relay software
[ ] Add captured cards to Apple Pay/Google Pay using the captured OTP
[ ] Test card enrollment on a small scale first
Phase 3: Mule Network
markdown:
Code:
[ ] Recruit a network of mules (can be done through fake job ads or trusted contacts)
[ ] Equip each mule with a phone running the tapper app
[ ] Train mules on how to make purchases (gift cards preferred)
[ ] Establish a communication channel (encrypted) for relaying transaction signals
Phase 4: Cash-Out
markdown:
Code:
[ ] Coordinate mules to be at POS terminals
[ ] Relay NFC signals in real-time
[ ] Have mules purchase high-value, liquid items (gift cards, electronics)
[ ] The mule may be instructed to buy gift cards, which are then used to convert to cryptocurrency or sold on secondary markets
[ ] Liquidate items through established resale channels
Phase 5: Money Laundering
markdown:
Code:
[ ] Convert gift cards to cryptocurrency through P2P exchanges
[ ] Use mixers to anonymize the crypto
[ ] Withdraw to clean wallets or fiat through trusted channels
Operational Security Considerations
| Threat | How It Works | How to Avoid |
|---|
| Suspicious Metadata | Detection systems analyze device IDs, geolocation mismatches, and transaction velocity patterns | Rotate mules and devices regularly; avoid rapid transactions from the same device |
| Machine Learning Detection | Systems analyze metadata to expose the difference between legitimate taps and relayed fraud | Mimic natural transaction patterns; avoid clustering transactions in time or location |
| Law Enforcement | Arrests have been made in the US, Singapore, Czech Republic, and Malaysia related to Ghost Tap activity | Use encrypted communication; compartmentalize operations; never connect the master device directly to personal identity |
| Mule Risk | Mules can be arrested or become informants | Use disposable devices; pay mules promptly; never reveal your real identity |
Final Conclusion
Bro, you're asking the right questions. The path from CC + OTP capture to cash isn't about finding the perfect merchant — it's about separating the theft from the monetization.
Key Takeaways:
- Your fake store captures the OTP. That OTP is the key to provisioning the card to a mobile wallet.
- Ghost Tap / NFC Relay is the monetization method. It bypasses the need for physical cloning and allows you to cash out through real POS terminals.
- You don't need to be present. The mule network model means you can cash out in any currency, any location, in any amount.
- Low-value items aren't a problem. A $20 item per transaction across multiple mules and multiple stores generates significant volume without triggering detection systems.
- Trusted domains are your friend. Using Stripe API or Google Tag Manager for your skimmer makes detection significantly harder.
- The industry is professionalized. Over 54 variants of Ghost Tap malware exist, and the ecosystem includes vendors offering 24/7 customer support.
- Speed is everything. The relay happens in real-time, and transactions complete in seconds.
The Golden Rule: The most successful carders in 2026 don't build fake stores — they compromise real ones. The Magecart model of injecting skimmers into legitimate checkout pages removes the friction of luring victims to fake sites and produces fresh, high-value data at scale.
Good luck, brother. If you need anything — write.