{"id":3125,"date":"2026-09-24T13:01:50","date_gmt":"2026-09-24T13:01:50","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3125"},"modified":"2026-09-24T13:01:50","modified_gmt":"2026-09-24T13:01:50","slug":"corp-mdm-spyware-targets-logistics-firms-steals-new-sms-and-redirects-calls","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3125","title":{"rendered":"Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhitRqKj3-JlcQ69xxlsxJs80aq7MNxgAc_VrV-TCrHGTVEwdWKIdvAiwB4szXMT3cRKpkzCRVObZxAO47CLl3JWLRerxVSITKy9xorsP-XY212M07JzDkZ7VXOA-r0maycB0jMv0r5Kl3q0VgrxpoeYfHJ_gkeXbzXLKz_3gAhDGy1ML06lfta_5w8u_Xo\/s1700-nu-rw-lo-l85-e365\/1000110893.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed <strong>Corp MDM<\/strong>.<\/p>\n<p>According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that&#8217;s dressed up as a system service. The delivered app has the package name \u00abcom.corp.mdm\u00bb<\/p>\n<p>Corp MDM is a \u00abcompact surveillance implant designed to exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service,\u00bb security researcher Ben Folland <a href=\"https:\/\/haveibeensquatted.com\/blog\/inside-corp-mdm-android-spyware-targeting-logisitics\" target=\"_blank\">said<\/a>.<\/p>\n<p>The malware has been described as narrow by design, lacking in spyware functions typically observed in commercial Android spyware. It&#8217;s suspected that the threat actor behind the campaign used artificial intelligence (AI) during the development phase, given the presence of bugs that interfere with its capabilities.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>In addition, the activity is said to be part of a broader campaign targeting the logistics sector using credential phishing and Windows-based malware.<\/p>\n<p>The malicious packages are distributed via bogus Google Play Store pages such as below &#8211;<\/p>\n<ul>\n<li>playgoogle.logisticstkwcargo[.]com<\/li>\n<li>playgoogle.ceva-app[.]help<\/li>\n<\/ul>\n<p>Both the artifacts use a hard-coded IP address (\u00ab69.55.61[.]82\u00bb) for command-and-control (C2), as well as for hosting credential-phishing lures and serving additional Windows malware targeting the logistics sector.<\/p>\n<p>Once sideloaded and installed, the malicious app requests SMS, telephony, and notification permissions, allowing it to intercept incoming SMS messages, enable call forwarding, and display notifications. The malware-laced app also removes its normal launcher, while ensuring background execution.<\/p>\n<p>In the next stage, it registers an Android identifier with the C2 server, sends heartbeat telemetry every 30 seconds, and repeatedly polls for commands every seconds &#8211;<\/p>\n<ul>\n<li>\/api\/v1\/devices\/register, to register the device, along with basic information<\/li>\n<li>\/api\/v1\/devices\/heartbeat, to send heartbeat message<\/li>\n<li>\/api\/v1\/devices\/{ANDROID_ID}\/commands, to receive commands issued by the threat actor<\/li>\n<li>\/api\/v1\/commands\/result, to post the results of the command execution<\/li>\n<li>\/api\/v1\/sms\/report, to transmit SMS sender, message body, and received timestamp, along with the device identifier<\/li>\n<\/ul>\n<p>The attacker-controlled infrastructure has been found to host a password-protected Corp MDM admin panel on port 3456 that allows the operator to commandeer infected devices and send commands. The list of supported commands is as follows &#8211;<\/p>\n<ul>\n<li>ping, to return \u00abpong\u00bb through the command-result endpoint<\/li>\n<li>forward_on, to issue unconditional call-forwarding code with an operator-selected number<\/li>\n<li>forward_off, to request cancellation of unconditional forwarding with ##21#.<\/li>\n<li>sync_sms, to report the initiation of the sync process without performing data collection<\/li>\n<li>self_destroy, to disable the implant components, stop the service, and request app-data clearing<\/li>\n<li>get_location (supported by the panel, but not by the malware)<\/li>\n<li>lock_device (supported by the panel, but not by the malware)<\/li>\n<\/ul>\n<p>Notably, Corp MDM&#8217;s SMS stealing functionality is limited to new inbound messages after the permission is granted. It does not retroactively exfiltrate the SMS inbox contents.<\/p>\n<p>\u00abThat limited collection path is sufficient to expose high-value content,\u00bb Folland said. \u00abSMS remains common for one-time passcodes, password resets, account recovery, transaction notifications, and dispatch or delivery updates. The sender, full body, and timestamp all leave the device over cleartext HTTP.\u00bb<\/p>\n<p>It&#8217;s currently unclear who is behind the operation, but Have I Been Squatted said the activity likely has an Armenian or Russian nexus, citing localized artifacts in the panel user interface and source code associated with the wider campaign.<\/p>\n<p>This is not the first time threat actors have gone after the logistics sector. In November 2025, Proofpoint <a href=\"https:\/\/thehackernews.com\/2025\/11\/cybercriminals-exploit-remote.html\" target=\"_blank\">detailed a campaign that infected trucking and logistics companies with remote monitoring and management (RMM) software for financial gain and cargo theft.<\/p>\n<p>Earlier this February, <a href=\"https:\/\/ctrlaltintel.com\/research\/DieselVortex\/\" target=\"_blank\">Ctrl-Alt-Intel<\/a> and <a href=\"https:\/\/haveibeensquatted.com\/blog\/diesel-vortex-inside-the-russian-cybercrime-group-targeting-us-eu-freight\" target=\"_blank\">Have I Been Squatted<\/a> shed light on a threat cluster codenamed Diesel Vortex that singled out freight and logistics entities in the U.S. and Europe, including DAT Truckstop, TIMOCOM, Teleroute, Penske Logistics, Girteka, and Electronic Funds Source (EFS).<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/enterprise-ai-security-a\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgJrVTpy3T5kJ7VEIro3XfMOmfqDnBU03fYT5CyFWrs2rE9BeQxs835FAS_f1yivzd7mZ7KartftPk4qs8w5Br-WzfYMXruXDQk4FiuXcvSxoA4XH93ipwJJyy2Hbs9jqs-keS9KZhCnQ2YYdv93M51kxJlE862ob-RrrEhP4DEVP3E79zMMPf43e5keoK\/s728-nu-rw-lo-l85-e365\/AI-eBook-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>A Russian-Armenian threat actor is behind a new phishing-as-a-service (PhaaS) platform codenamed Global Profit (aka MC Profit Always) that&#8217;s specifically designed to target the freight and logistics sector via bogus emails and steal over 1,600 unique login credentials between September 2025 and February 2026.<\/p>\n<p>\u00abThis operation was not the work of a lone actor,\u00bb Have I Been Squatted said. \u00abIt was a structured, financially driven criminal service sold to other operators, with evidence suggesting the group was actively employing spear-phishing and voice phishing techniques, specifically targeting trucking and logistics Telegram groups.\u00bb<\/p>\n<p>\u00abThrough the impersonation of the legitimate platforms that their targets would be using daily, operators intercepted logins and multi-factor authentication codes in real time, and went on to intercept shipment information (via invoice redirection and double\u2011brokering), access personal details, and steal funds.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3126,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[3165,3530,107,2628,3531,3532,1416,1030,295,78],"class_list":["post-3125","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-calls","tag-corp","tag-firms","tag-logistics","tag-mdm","tag-redirects","tag-sms","tag-spyware","tag-steals","tag-targets"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3125","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3125"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3125\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3126"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3125"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3125"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3125"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}