Threat Intelligence

Fake Logistics Apps Hide 'Corp MDM' Spyware That Steals SMS and Hijacks Calls

The Hacker News · 24 Sept 2026
Key Takeaway Only install apps from official app stores, never sideload APK files from links in emails or messages, and be wary of unofficial download pages branded as trusted logistics companies.

Security researchers have uncovered a malicious campaign targeting the logistics industry with an Android spyware tool named Corp MDM. Attackers are creating fake Google Play Store pages branded to look like CEVA and TKW Logistics, tricking victims into downloading an app disguised as a system service. Once installed, the app hides itself, requests SMS and call permissions, and quietly runs in the background.

After installation, Corp MDM registers the infected device with an attacker-controlled server, checks in regularly, and waits for commands. It can intercept new incoming SMS messages and forward calls, though it cannot access messages already stored on the device before infection. Researchers believe the malware may have been partly built using AI tools, based on bugs found in its code. The same infrastructure hosting Corp MDM has also been linked to credential phishing pages and separate Windows-based malware, suggesting a wider campaign against logistics businesses.

This type of attack relies on employees sideloading apps from outside official app stores, often after being lured by convincing fake branding. Because the malware targets SMS, it could be used to intercept one-time passwords or verification codes sent to staff phones.

Android spyware logistics sector mobile security phishing malware

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.