Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
- ID
- 28074
- Status
- summarized
- Published
- 24 Sep 2026, 8:05 PM
- Fetched
- 24 Sep 2026, 8:21 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.0
- Created
- 24 Sep 2026, 8:22 PM
- Tags
- Audience
- developerssaas_startup_founders
What happened
A campaign dubbed Corp MDM is distributing Android spyware via fake Google Play pages branded as logistics companies CEVA and TKW Logistics, delivering an APK named "com.corp.mdm" disguised as a system service. The implant requests SMS, telephony and notification permissions, then exfiltrates newly received SMS, enables call forwarding, hides its launcher and polls a hard-coded C2 IP (69.55.61[.]82) every 30 seconds via endpoints like /api/v1/devices/register and /api/v1/sms/report. Researcher Ben Folland described it as a narrow implant, and the report says AI was suspected in its development because bugs interfere with its capabilities; the same infrastructure also hosts credential-phishing lures and Windows malware aimed at the logistics sector.
Why it matters
The delivery vector is a sideloaded APK from a lookalike Play page (playgoogle.ceva-app[.]help, playgoogle.logisticstkwcargo[.]com), not the Play Store itself, so anyone running driver, fleet or warehouse ops apps on Android should treat APK links from email/chat as hostile and check device logs or network egress for 69.55.61[.]82. The malware's whole value is intercepting incoming SMS and forwarding calls, which is exactly the channel many SEA teams still use for OTP and dispatch confirmations, so a compromised field handset can hand over account resets, not just messages.
Discussion angle
If your product or ops depends on Android handsets in the field, how do you enforce install sources and detect a hidden foreground service that only polls outbound every 30 seconds - and would blocking one C2 IP actually help?