Skip to content
Corp MDM Spyware Targets Logistics Sector via Fake Google Play Pages

Corp MDM Spyware Targets Logistics Sector via Fake Google Play Pages

First seen 24 Sep 2026, 13:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 24, 2026 at 14:59 UTC
  • Corp MDM spyware targets logistics firms via fake Google Play pages.
  • The malware exfiltrates SMS and redirects calls while maintaining a hidden service.
  • The campaign is linked to broader phishing and malware activities with potential ties to Russian and Armenian actors.

A malware campaign has emerged targeting the logistics sector, distributing Android spyware named Corp MDM through counterfeit Google Play pages branded as CEVA and TKW Logistics. The malicious APK, disguised as a system service, is designed to exfiltrate SMS content, divert calls, and operate a hidden service. The spyware is characterized as narrow in functionality, lacking the extensive features typical of commercial spyware, and is believed to have been developed with AI assistance, evidenced by bugs that limit its effectiveness. The broader campaign also includes credential phishing and Windows malware, with ties to Armenian and Russian threat actors. The command-and-control infrastructure uses a hardcoded IP address for both the spyware and phishing activities. The malware requests permissions to intercept SMS and calls, and it maintains a persistent background presence. Security experts have noted that the campaign may facilitate cargo theft by collecting sensitive logistics information.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-24
Corp MDM spyware campaign reported
The logistics sector is targeted by a malware campaign distributing Android spyware through fake Google Play pages.
haveibeensquatted.com
2026-09-24
Details of spyware functionality revealed
The spyware is designed to exfiltrate SMS and divert calls, operating as a hidden service.
Thehackernews
2026-09-24
Command-and-control infrastructure identified
The spyware uses a hardcoded IP address for command and control, also hosting phishing lures.
Thehackernews

More articles in this cluster (2)

Following this threat?

Track Corp MDM and CEVA in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed