A new cyber campaign targeting the logistics sector has been identified distributing an Android spyware known as Corp MDM, according to cybersecurity researchers. The malware campaign uses fake Google Play pages designed to appear associated with logistics companies, including CEVA and TKW Logistics, to distribute malicious Android Package Kit files. Researchers said the spyware is designed to steal newly received SMS messages, redirect phone calls, and maintain hidden background activity on infected devices. The discovery highlights increasing concerns around mobile threats targeting industries that rely heavily on communication systems, shipment updates, authentication messages, and operational data.
According to security researcher Ben Folland from Have I Been Squatted, Corp MDM is a compact surveillance implant that focuses on specific monitoring capabilities rather than offering a broad set of spyware features commonly seen in commercial mobile surveillance tools. The malicious application is distributed through fraudulent Google Play pages, including domains such as playgoogle.logisticstkwcargo[.]com and playgoogle.ceva-app[.]help. Researchers found that the delivered application uses the package name “com.corp.mdm” and is disguised as a system service to appear legitimate. Once installed, the application requests permissions related to SMS messages, phone calls, and notifications, allowing it to intercept incoming messages, activate call forwarding features, and continue operating without drawing attention. The malware also removes its normal launcher presence while maintaining background execution through a hidden service.
Researchers said the malware connects to attacker-controlled infrastructure using a hard coded IP address, which is also used for command and control operations, credential phishing pages, and hosting additional Windows based malware targeting logistics organizations. After installation, the application registers the infected device with a command and control server, sends periodic heartbeat information, and regularly checks for instructions from the operator. The communication process includes device registration, status updates, command retrieval, command execution reporting, and SMS data transmission. The collected SMS information includes sender details, message content, timestamps, and device identifiers. Security researchers noted that the malware only collects newly received SMS messages after permissions are granted and does not appear to extract previous messages stored on the device.
The attacker controlled infrastructure reportedly includes a password protected Corp MDM administration panel that allows operators to manage infected devices and issue commands. Available commands identified by researchers include options for checking device communication, enabling or disabling unconditional call forwarding, initiating SMS synchronization requests, and disabling the malware components through a self destruction function. Researchers also found additional functions displayed in the administration panel, including location retrieval and device locking features, although those capabilities were reportedly not supported by the malware itself. Folland noted that despite its limited collection capabilities, the spyware could expose sensitive information because SMS messages are frequently used for one time passwords, account recovery notifications, transaction alerts, and delivery updates. Researchers also highlighted concerns that the collected information was transmitted over cleartext HTTP connections.
The identity of the group behind the campaign remains unclear, although researchers suggested possible Armenian or Russian links based on localized elements found in the malware infrastructure and source code. The campaign is part of broader cyber activity targeting logistics organizations through phishing and malware distribution. Previous security investigations have also identified campaigns targeting freight and transportation companies through remote monitoring tools, credential theft operations, and phishing services. Researchers have warned that logistics firms remain attractive targets because their systems often contain valuable operational information, shipment details, financial data, and access credentials. As cybercriminal groups continue adapting their methods, organizations in the logistics sector are being encouraged to strengthen mobile security controls, verify application sources, monitor unusual device behaviour, and implement stronger authentication practices to reduce exposure to emerging threats.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.