Security Researchers at Trend Micro have come up with a new discovery revealing the successful hacking of RFID payment cards using simple Android App. Researchers found a high-risk rated android app detected as ANDROID_STIP.A in chile. The app can be used to hack into the user's RFID bus transit card to recharge the credits.
With more and more use of NFC, and apple also making mind to bring NFC to their devices, its becoming more familiar to pay using RFID cards. Banks, merchants or public services issue RFID cards to their customers with prepaid credits.
Security Issues with RFID Cards
RFID cards are MIFARE-based smartcards; MIFARE refers to a family of chips widely used in contactless smart cards and proximity cards.
The code of the android app brings the researchers to the conclusion that, if it runs on a device equipped with NFC, it can read and write to these cards. The malicious app can raise the user card balance to 10,000 Chilean pesos (approx 15 USD), by writing predefined data on the card. This particular hack is restricted to this particular FARE card, since it depends on the format of the card.
The older version of MIFARE series cards (MIFARE Classic) is known to have multiple security issues. New cards are based on this older version. An attacker is able to clone or modify a MIFARE Classic card in under 10 seconds, and the equipment (such as the Proxmark3), together with any needed support, is sold online.
With the use of widely available tools, the attacker can crack the card's authentication key. After this, the cracked authentication and common NFC support in Android and the device can be used to clone a card and add credits by easily implementing this in a mobile app.

Trendmicro said, Attacks on other series of MIFARE cards (specifically, MIFARE DESFire and MIFARE Ultraight) are being done. Three cards have been found to be vulnerable, these are, a social security card with banking service, a payment card for transportation and shopping, and a dining card. The social security card has approximately seven million users.

Since the Dining card uses the older version of MIFARE series i.e. MIFARE Classic, so the on-card details can be changed. The two other cards are MIFARE DESFire cards, which are vulnerable to side-channel attacks. The cryptosystems in these cards leak information if the power used is monitored; the keys can be recovered within seven hours. If the issued keys are not random, customer cards can be cloned or manipulated similarly to MIFARE Classic cards. Or even worse, credits can also be manipulated within a NFC-enabled mobile device.
The app is said to be distributed through forums and blogs.
Conclusion
These particular MIFARE models were discontinued years ago and supplemented with more secure models. However, it appears that card issuers have opted for cheaper solutions which put their customers at risk.
Users are advised to take steps to protect RFID cards in their possession. They should also periodically check the balances of their accounts as well. In addition, if possible, they should check if any cards they are currently using are vulnerable and report these to their providers.