A campaign distributing Android spyware codenamed Corp MDM targets the logistics sector using fake Google Play pages branded as CEVA and TKW Logistics, hosted at playgoogle.logisticstkwcargo[.]com and playgoogle.ceva-app[.]help, which deliver an APK named com.corp.mdm dressed as a system service. Researcher Ben Folland (Have I Been Squatted) describes the implant as deliberately narrow: it exfiltrates newly received SMS content, diverts calls, requests SMS, telephony and notification permissions, removes its own launcher icon and maintains a hidden foreground service. Both lures and the malware use a hard-coded command-and-control address (69.55.61[.]82), which also hosts credential-phishing pages and Windows malware aimed at the same sector, indicating this is one operation rather than an isolated app. Folland notes the implant lacks the breadth of commercial Android spyware and contains implementation bugs, and suggests AI assistance in development.
| Attribute | Detail |
|---|---|
| Sector | Transport |
| Date | 2026-09-25 |
| Source | The Hacker News |
| Reliability | Tier 2 |