A new Android spyware variant named Corp MDM targets logistics companies through fraudulent distribution channels mimicking legitimate enterprise software. Security researchers at Have I Been Squatted identified the malware distributed via counterfeit Google Play pages impersonating CEVA and TKW Logistics, two major supply chain operators.
The attack vector relies on social engineering. Threat actors created fake Google Play storefronts branded with company logos and branding that closely resemble legitimate app pages. Workers in logistics operations, accustomed to downloading enterprise tools, encounter these pages and install the malware believing they are downloading genuine corporate applications. The malicious package uses the identifier "com.corp.mdm" and presents itself as a system service to evade detection.
Corp MDM performs invasive surveillance once installed. The spyware intercepts and exfiltrates SMS messages, enabling attackers to harvest sensitive communications including two-factor authentication codes, shipment notifications, and inter-company coordination messages. The malware also intercepts and redirects incoming calls, routing them to attacker-controlled numbers. This capability allows threat actors to intercept voice communications and potentially conduct social engineering attacks or access restricted information by impersonating legitimate contacts.
Logistics firms handle time-sensitive shipments, vendor communications, and financial transactions. Compromised devices in dispatch centers, warehouses, or management offices expose operational data, customer information, and financial details. Call redirection poses particular risk in an industry dependent on rapid communication between drivers, dispatchers, and clients. Attackers could intercept delivery coordinates, access codes for facilities, or payment authorization calls.
The campaign demonstrates a maturation in Android malware distribution tactics. Rather than relying solely on third-party app stores, attackers created convincing replica pages within Google Play itself, exploiting the platform's organic traffic and trust associations. This approach bypasses email-based phishing and targets users already in the mindset of downloading work applications.
The logistics sector presents an attractive target for multiple threat actor motivations. Nation-state actors monitor supply chains for intelligence gathering. Criminal groups target payment information and shipment data for theft or resale. Competitors may seek operational intelligence. The sector's distributed workforce and varied device security postures create entry points.
Organizations in logistics should implement strict mobile device management policies requiring employees to download applications only from official company portals or primary app store listings, never from search results or links in communications. Two-factor authentication should avoid SMS-based codes where possible, replacing them with authenticator apps or hardware keys. Firms should audit employee device installations and deploy mobile threat detection tools.
Endpoint detection and response solutions should flag applications attempting to intercept SMS messages or redirect calls, behaviors rarely legitimate outside specialized carrier applications. Network monitoring should identify unusual outbound connections from employee devices, particularly those connecting to infrastructure associated with previous malware campaigns.
The discovery adds to growing evidence that supply chain software remains a preferred attack vector. Previous campaigns targeting logistics firms deployed malware through compromised supplier portals and fraudulent update mechanisms. This campaign's reliance on fake app store pages represents an evolution in targeting distribution channels where victims expect to find legitimate tools.
