The logistics sector is being targeted by a new malicious cyber campaign distributing Android spyware called Corp MDM. This malware is delivered through fake Google Play pages, impersonating companies like CEVA and TKW Logistics, to distribute an Android Package Kit (APK) file disguised as a system service.
Corp MDM is a compact surveillance implant designed to exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service. It requests SMS, telephony, and notification permissions upon installation, allowing it to intercept messages and enable call forwarding. The app also removes its launcher icon and ensures background execution.
The malicious packages use a hard-coded IP address (69.55.61.82) for command-and-control (C2) communications. This infrastructure also hosts credential-phishing lures and serves additional Windows malware. Infected devices register with the C2 server, send heartbeat telemetry, and poll for commands, reporting results and transmitting SMS data.
This Android spyware activity is part of a broader campaign targeting the logistics sector, which includes credential phishing and Windows-based malware. Researchers suspect artificial intelligence (AI) may have been used in the development of Corp MDM due to the presence of bugs that hinder its full capabilities.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new Android spyware named Corp MDM is targeting the logistics sector through fake Google Play pages, exfiltrating SMS content and diverting calls. The malware is part of a broader campaign that also includes credential phishing and Windows-based malware, indicating a focused attack on logistics companies.