Skip to content
Corp MDM spyware targets logistics firms, steals new SMS and redirects calls

Corp MDM spyware targets logistics firms, steals new SMS and redirects calls

News.Lavx.Hu • September 24, 2026

A malicious Android app posing as a logistics system service can forward calls, capture new SMS messages and send device data to attacker-controlled servers. The campaign also links to phishing pages and Windows malware aimed at freight companies.

A malicious Android app known as Corp MDM targets logistics workers through fake Google Play pages branded as CEVA and TKW Logistics. Once installed, the spyware can capture new SMS messages, redirect calls and maintain background access to an infected phone.

Researchers at Have I Been Squatted found the campaign during an investigation into attacks against logistics companies. The malware uses the Android package name com.corp.mdm and disguises itself as a system service.

A narrow surveillance tool

Security researcher Ben Folland described Corp MDM as a small surveillance implant built around SMS theft, call forwarding and a hidden foreground service. The app does not include the broad feature set found in commercial Android spyware.

After installation, Corp MDM requests access to SMS, phone calls and notifications. It removes its launcher icon, keeps its service running and registers the device with an attacker-controlled server.

The malware sends device details to the server, checks for commands and reports command results. Its network activity includes these paths:

/api/v1/devices/register registers the device and sends basic information.

/api/v1/devices/heartbeat sends a heartbeat every 30 seconds.

/api/v1/devices/{ANDROID_ID}/commands retrieves operator commands.

/api/v1/commands/result reports command results.

/api/v1/sms/report sends SMS sender details, message text, timestamp and device information.

The operator can use the panel to send ping , enable or disable unconditional call forwarding, trigger a limited SMS sync report or destroy the implant. The panel also lists location and device-lock commands, but Corp MDM does not support those functions.

SMS theft can expose business accounts

Corp MDM collects messages that arrive after the app receives SMS permission. It does not copy the existing inbox.

That limit still gives attackers access to one-time passcodes, password resets, account recovery messages, transaction alerts and dispatch updates. The malware sends the sender, message body and timestamp to the server through unencrypted HTTP.

Android users can review app access through the Android permissions guide . Organizations should remove unknown apps with SMS or phone permissions and review devices that received installation instructions through email, text messages or workplace chat.

Security teams should also check mobile network accounts for unexpected call-forwarding changes. An attacker who redirects calls can intercept voice-based verification and disrupt communication with drivers, dispatchers or customers.

Fake Play pages support a wider campaign

Investigators identified two fake distribution pages:

playgoogle.logisticstkwcargo[.]com

playgoogle.ceva-app[.]help

Both sites use the hard-coded IP address 69.55.61[.]82 for command and control, phishing pages and additional Windows malware. The same infrastructure links the Android operation to a broader campaign against freight and logistics companies.

The attacker-controlled server also hosts a password-protected Corp MDM administration panel on port 3456. Researchers found localized interface elements and source-code clues that point to an Armenian or Russian connection, but they have not identified the operators.

Researchers suspect the developer used AI during development because bugs interfere with some advertised functions. That conclusion remains an assessment, not proof of the developer's identity or workflow.

Logistics companies face layered attacks

Corp MDM fits a wider pattern of attacks against freight businesses. Proofpoint reported a November 2025 campaign that used remote monitoring and management software in attacks linked to financial theft and cargo theft.

Ctrl-Alt-Intel and Have I Been Squatted also documented Diesel Vortex, a threat cluster that targeted logistics entities in the United States and Europe. The named targets included DAT Truckstop, TIMOCOM, Teleroute, Penske Logistics, Girteka and Electronic Funds Source.

Researchers have linked another service, Global Profit, also called MC Profit Always, to phishing campaigns against freight companies. The service collected more than 1,600 unique credentials between September 2025 and February 2026, according to the supplied research.

Attackers used fake versions of platforms that trucking staff rely on each day. They captured passwords and multifactor authentication codes, then pursued shipment data, invoice redirection, double-brokering opportunities and stolen funds.

Logistics companies can reduce exposure by taking four actions:

Block installation from unknown sources on managed Android devices and enforce approved app stores through mobile-device management.

Review SMS, phone, notification and accessibility permissions for every managed device.

Monitor DNS, proxy and firewall logs for connections to 69.55.61[.]82 and the listed phishing domains.

Reset credentials and revoke sessions after a worker enters information into a fake logistics login page.

Administrators should inspect Android devices for an app named Corp MDM, the package com.corp.mdm , missing launcher icons and unexpected call-forwarding settings. Teams should check Windows endpoints for related malware and review email, browser and identity-provider logs for credential theft.

Google provides guidance on Google Play Protect , but organizations should pair it with managed-device controls, phishing-resistant authentication and staff training. SMS codes protect accounts less effectively than passkeys or hardware security keys, especially when malware can read messages or redirect calls.

Please log in or register to join the discussion