← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Corp MDM Android Spyware Targets Logistics Firms, Steals SMS and Redirects Calls

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Corp MDM spyware targets logistics companies via fake Google Play pages.
  • Malware steals SMS content, redirects calls, and maintains hidden service.
  • Uses hard-coded IP for command-and-control and additional malware hosting.
  • Campaign also involves credential phishing and Windows malware.

New Android Spyware Campaign

The logistics sector is being targeted by a new malicious cyber campaign distributing Android spyware called Corp MDM. This malware is delivered through fake Google Play pages, impersonating companies like CEVA and TKW Logistics, to distribute an Android Package Kit (APK) file disguised as a system service.

Corp MDM Capabilities

Corp MDM is a compact surveillance implant designed to exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service. It requests SMS, telephony, and notification permissions upon installation, allowing it to intercept messages and enable call forwarding. The app also removes its launcher icon and ensures background execution.

Infrastructure and Communication

The malicious packages use a hard-coded IP address (69.55.61.82) for command-and-control (C2) communications. This infrastructure also hosts credential-phishing lures and serves additional Windows malware. Infected devices register with the C2 server, send heartbeat telemetry, and poll for commands, reporting results and transmitting SMS data.

Broader Campaign and Suspected AI Use

This Android spyware activity is part of a broader campaign targeting the logistics sector, which includes credential phishing and Windows-based malware. Researchers suspect artificial intelligence (AI) may have been used in the development of Corp MDM due to the presence of bugs that hinder its full capabilities.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~24 min · 20 stories · Sep 24

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A new Android spyware named Corp MDM is targeting the logistics sector through fake Google Play pages, exfiltrating SMS content and diverting calls. The malware is part of a broader campaign that also includes credential phishing and Windows-based malware, indicating a focused attack on logistics companies.