The logistics industry is grappling with a fresh cybersecurity threat as a new Android spyware, named Corp MDM, is being deployed to infiltrate the sector. This malicious software is disseminated through counterfeit Google Play Store sites, masquerading as legitimate logistics service providers like CEVA and TKW Logistics.
How Corp MDM Operates
Corp MDM is an Android Package Kit (APK) that appears as a system service under the package name “com.corp.mdm.” The spyware is specifically designed to extract newly received SMS messages, redirect calls, and sustain a stealthy foreground service. Security researcher Ben Folland describes the spyware as limited in scope, lacking many features typical of commercial Android spyware. It is believed that artificial intelligence may have played a role in its development, given the bugs present that hinder its functionality.
Despite its limitations, Corp MDM is part of a more extensive campaign targeting the logistics sector through phishing and Windows-based malware. The fake Google Play Store pages distributing the spyware include domains like playgoogle.logisticstkwcargo[.]com and playgoogle.ceva-app[.]help. These sites also host credential phishing schemes and additional malware aimed at logistics companies.
Technical Details and Impact
Once installed, the malicious app requires permissions to intercept SMS, enable call forwarding, and display notifications. It removes its launcher icon to avoid detection, while continuously running in the background. The app connects to a command-and-control server using a hard-coded IP address and sends regular updates and command requests.
The command infrastructure allows attackers to control infected devices, issuing commands like “ping” to check connectivity, “forward_on” to enable call forwarding, and “self_destroy” to erase the spyware from the device. Notably, the spyware’s ability to steal SMS messages is limited to new ones received after permission is granted, but this is enough to compromise sensitive information like one-time passcodes and transaction notifications.
Potential Origins and Previous Incidents
The identity of the threat actor behind Corp MDM remains unknown, but there are indications of an Armenian or Russian connection, based on localized elements in the spyware’s panel interface and source code. This is not an isolated attack on the logistics sector; previous incidents, such as a 2025 campaign using remote monitoring and management software, have targeted this industry for financial exploitation and cargo theft.
Moreover, a phishing-as-a-service platform, dubbed Global Profit, has been linked to phishing attacks targeting logistics firms, with a focus on intercepting login credentials and shipment information. This service was structured as a criminal enterprise, employing spear-phishing and voice phishing tactics to deceive logistics companies.
In conclusion, the logistics industry continues to be a lucrative target for cybercriminals. As this sector remains vulnerable to sophisticated cyber attacks, organizations must bolster their cybersecurity measures to protect sensitive data and maintain operational integrity.
