Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Android Spyware Targets Logistics Sector

New Android Spyware Targets Logistics Sector

Posted on September 24, 2026 By CWS

The logistics industry is grappling with a fresh cybersecurity threat as a new Android spyware, named Corp MDM, is being deployed to infiltrate the sector. This malicious software is disseminated through counterfeit Google Play Store sites, masquerading as legitimate logistics service providers like CEVA and TKW Logistics.

How Corp MDM Operates

Corp MDM is an Android Package Kit (APK) that appears as a system service under the package name “com.corp.mdm.” The spyware is specifically designed to extract newly received SMS messages, redirect calls, and sustain a stealthy foreground service. Security researcher Ben Folland describes the spyware as limited in scope, lacking many features typical of commercial Android spyware. It is believed that artificial intelligence may have played a role in its development, given the bugs present that hinder its functionality.

Despite its limitations, Corp MDM is part of a more extensive campaign targeting the logistics sector through phishing and Windows-based malware. The fake Google Play Store pages distributing the spyware include domains like playgoogle.logisticstkwcargo[.]com and playgoogle.ceva-app[.]help. These sites also host credential phishing schemes and additional malware aimed at logistics companies.

Technical Details and Impact

Once installed, the malicious app requires permissions to intercept SMS, enable call forwarding, and display notifications. It removes its launcher icon to avoid detection, while continuously running in the background. The app connects to a command-and-control server using a hard-coded IP address and sends regular updates and command requests.

The command infrastructure allows attackers to control infected devices, issuing commands like “ping” to check connectivity, “forward_on” to enable call forwarding, and “self_destroy” to erase the spyware from the device. Notably, the spyware’s ability to steal SMS messages is limited to new ones received after permission is granted, but this is enough to compromise sensitive information like one-time passcodes and transaction notifications.

Potential Origins and Previous Incidents

The identity of the threat actor behind Corp MDM remains unknown, but there are indications of an Armenian or Russian connection, based on localized elements in the spyware’s panel interface and source code. This is not an isolated attack on the logistics sector; previous incidents, such as a 2025 campaign using remote monitoring and management software, have targeted this industry for financial exploitation and cargo theft.

Moreover, a phishing-as-a-service platform, dubbed Global Profit, has been linked to phishing attacks targeting logistics firms, with a focus on intercepting login credentials and shipment information. This service was structured as a criminal enterprise, employing spear-phishing and voice phishing tactics to deceive logistics companies.

In conclusion, the logistics industry continues to be a lucrative target for cybercriminals. As this sector remains vulnerable to sophisticated cyber attacks, organizations must bolster their cybersecurity measures to protect sensitive data and maintain operational integrity.

The Hacker News Tags:Android spyware, call redirection, cyber attack, cyber threat, Cybersecurity, data breach, financial gain, logistics cybersecurity, logistics security, Malware, phishing attacks, phishing techniques, SMS interception, tech news, Threat Actors

Post navigation

Previous Post: NIST and CISA/FBI Issue Crucial OT Security Updates
Next Post: Island Secures $400M Funding, Reaches $6.4B Valuation

Related Posts

Adobe Tackles Major Security Flaws in ColdFusion and Campaign Adobe Tackles Major Security Flaws in ColdFusion and Campaign The Hacker News
CISA Identifies Exploited Wing FTP Vulnerability CISA Identifies Exploited Wing FTP Vulnerability The Hacker News
Critical cPanel Vulnerabilities Allow Root Access and Server Control Critical cPanel Vulnerabilities Allow Root Access and Server Control The Hacker News
TikTok Settles 0M U.S. Child Privacy Lawsuit TikTok Settles $400M U.S. Child Privacy Lawsuit The Hacker News
Critical Check Point VPN Certificate Flaws Patched Critical Check Point VPN Certificate Flaws Patched The Hacker News
Thomson Reuters Data Breach Affects Multiple Court Systems Thomson Reuters Data Breach Affects Multiple Court Systems The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft’s AI-Driven SOC Enhancements with SIEM Integration
  • Island Secures $400M Funding, Reaches $6.4B Valuation
  • New Android Spyware Targets Logistics Sector
  • NIST and CISA/FBI Issue Crucial OT Security Updates
  • ClickFix: How Trusted Sites Become Malware Traps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft’s AI-Driven SOC Enhancements with SIEM Integration
  • Island Secures $400M Funding, Reaches $6.4B Valuation
  • New Android Spyware Targets Logistics Sector
  • NIST and CISA/FBI Issue Crucial OT Security Updates
  • ClickFix: How Trusted Sites Become Malware Traps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark