haveibeensquatted.com Corp MDM Spyware Targets Logistics Sector via Fake Google Play Pages
Article Content
- •Corp MDM spyware targets logistics firms via fake Google Play pages.
- •The malware exfiltrates SMS and redirects calls while maintaining a hidden service.
- •The campaign is linked to broader phishing and malware activities with potential ties to Russian and Armenian actors.
A malware campaign has emerged targeting the logistics sector, distributing Android spyware named Corp MDM through counterfeit Google Play pages branded as CEVA and TKW Logistics. The malicious APK, disguised as a system service, is designed to exfiltrate SMS content, divert calls, and operate a hidden service. The spyware is characterized as narrow in functionality, lacking the extensive features typical of commercial spyware, and is believed to have been developed with AI assistance, evidenced by bugs that limit its effectiveness. The broader campaign also includes credential phishing and Windows malware, with ties to Armenian and Russian threat actors. The command-and-control infrastructure uses a hardcoded IP address for both the spyware and phishing activities. The malware requests permissions to intercept SMS and calls, and it maintains a persistent background presence. Security experts have noted that the campaign may facilitate cargo theft by collecting sensitive logistics information.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Corp MDM and CEVA in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Diesel Vortex: Russian Cybercrime Group Targets US and EU Freight Companies In February 2026, the cybercrime group Diesel Vortex was uncovered, targeting freight and logistics companies in the US and EU. The group employed phishing-as-a-service tactics, harvesting over 1,600 unique login credentials from major logistics platforms. Their operations included impersonation of legitimate carriers…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…