$ techbeacon▋
Darkweb

Android Spyware ‘Corp MDM’ Hijacks Logistics Apps via Fake Play Store Pages

Android Spyware ‘Corp MDM’ Hijacks Logistics Apps via Fake Play Store Pages

A new Android-based espionage tool, dubbed Corp MDM, is being used to infiltrate logistics companies by masquerading as legitimate applications on counterfeit Google Play listings. Security researchers at Have I Been Squatted identified the malware on fake store pages that pretended to represent well‑known freight firms CEVA and TKW Logistics, tricking employees into installing the malicious package on their devices.

Once installed, Corp MDM operates as a mobile device management (MDM) backdoor, granting its operators the ability to read newly received SMS messages and to reroute voice calls. These capabilities allow threat actors to intercept one‑time passwords, authentication codes, and other sensitive communications that logistics staff rely on for shipment tracking, driver coordination, and client verification.

The campaign highlights a growing trend of supply‑chain and transportation firms becoming prime targets for cyber‑espionage. The logistics sector handles high‑value goods and time‑critical data, making it attractive to actors seeking to disrupt operations or harvest commercial intelligence. By exploiting the trust employees place in familiar brand names on official app stores, the attackers bypass many traditional security controls that focus on network‑level defenses.

Industry analysts note that Android’s open ecosystem, combined with the widespread use of personal devices for work purposes, creates a fertile environment for such attacks. While the malicious APKs were distributed through fake pages, the underlying code appears to be custom‑written, suggesting a dedicated effort rather than a repackaged off‑the‑shelf trojan. The researchers have not publicly linked the operation to a specific nation‑state or criminal group, but the sophistication of the delivery method aligns with previously observed supply‑chain intrusion tactics.

Experts recommend that logistics companies enforce stricter mobile‑device policies, including verification of app sources, the use of reputable mobile‑device‑management solutions, and employee training on phishing and app‑spoofing threats. Ongoing monitoring for abnormal call routing and unexpected SMS access can also help detect the presence of Corp MDM early. As the investigation continues, the incident serves as a reminder that cyber threats are increasingly leveraging everyday consumer platforms to reach high‑value business targets.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related