Fake Logistics Apps Hide 'Corp MDM' Spyware That Steals SMS and Hijacks Calls
Security researchers have uncovered a malicious campaign targeting the logistics industry with an Android spyware tool named Corp MDM. Attackers are creating fake Google Play Store pages branded to look like CEVA and TKW Logistics, tricking victims into downloading an app disguised as a system service. Once installed, the app hides itself, requests SMS and call permissions, and quietly runs in the background.
After installation, Corp MDM registers the infected device with an attacker-controlled server, checks in regularly, and waits for commands. It can intercept new incoming SMS messages and forward calls, though it cannot access messages already stored on the device before infection. Researchers believe the malware may have been partly built using AI tools, based on bugs found in its code. The same infrastructure hosting Corp MDM has also been linked to credential phishing pages and separate Windows-based malware, suggesting a wider campaign against logistics businesses.
This type of attack relies on employees sideloading apps from outside official app stores, often after being lured by convincing fake branding. Because the malware targets SMS, it could be used to intercept one-time passwords or verification codes sent to staff phones.