Corp MDM: Android spyware points to the logistics sector, steals SMS and miscalls

Author: Published 6 min de lectura 16 reading

The images in this article were generated with artificial intelligence. How we publish

A new operation directed against the logistics sector uses an Android spyware identified as Corp MDM, which is being distributed through fraudulent pages that imitate Google Play and industry brands. Researchers who follow the campaign - including the analyst Ben Folland and the project Have I Been Squatted - have documented APK packages with the name of a "com.corp.mdm" package hosted in sites such as playgoogle.logisticstkwcargo [.] com and playgoogle.ceva-app [.] help, and communicating with a fixed IP address (69.55.61.82) used both for infection control and for hosting phishing and Windows signs.

Confirmed facts: according to the technical analysis published by the researchers, Corp MDM is a compact implant designed for exfilter incoming SMS, redirect calls and stay hidden in background execution. The malware requests SMS permissions, telephony and notifications after installation, removes its icon from the start screen (launcher) to hide and establishes regular communication with a command and control server (C2) using HTTP routes such as / api / v1 / devices / register, / api / v1 / devices / heart beat, / api / v1 / devices / {ANDROID _ ID} / commands and / api / v1 / sms / report. The management panel hosted in the attacking infrastructure listens at port 3456 and provides remote commands - ping, forward _ on, forward _ off, sync _ sms, self _ destroy - that allow, for example, to activate the unconditional diversion of calls to a number controlled by the attacker or to request the sending of newly received SMS.

Corp MDM: Android spyware points to the logistics sector, steals SMS and miscalls
Image generated with IA.

How it works technically: the documented operating flow is as follows. First, the victim downloads and installs the APK from a page that imitates Google Play (sideloadeo). When granting permits, the application can intercept incoming SMS and send its content (sender, body and time mark) to C2 by using HTTP in clear. The application records an Android identifier on the server, sends periodic beats (every ~ 30 seconds) and consults commands. Call redirection orders are run by GSM codes (e.g., activation of the operator -selected number and cancellation using # # 21 #), and there is a self-deleted order that aims to disable the implant and clean up the app data.

Limitations and anomalies observed: analysts describe Corp MDM as "narrow by design"- lacks many regular capabilities in commercial spyware and only captures SMS received from the moment permits are granted; it does not make a retroactive turn of the SMS mailbox. In addition, the software contains implementation errors that have led to the hypothesis that artificial intelligence was used during its development to accelerate production, which would have introduced bugs that limit its effectiveness. It is also significant that exfiltration is done by HTTP without encryption, which facilitates its detection in networks that inspect outgoing traffic.

Who affects and why it matters: the campaign is directed to the logistics ecosystem - transport operators, parcel companies, drivers and personnel handling notifications by SMS - where single-use codes, shipping confirmations, invoice readdresses or changes in delivery instructions are valuable signs for fraud or cargo theft. The requested permissions allow intercept SMS authentication codes (OTP) and critical notifications, and the call diversion control opens the door to interception of telephone checks or fraudulent coordination with field staff.

Real plausible consequences: with the data extracted and access to telephone communications, a malicious operator can make suplantations (account takeover), financial fraud, redirection of shipments (investment redirection, double-breaking) and coordination to appropriate charges. Although Corp MDM seems less elaborate than other commercial families, its ability to capture sensitive content in real time is sufficient to compromise processes that depend on SMS and calls.

Attribution and context: Have I Been Squated points to signs of an Armenian or Russian nexus in artifacts located in the panel interface and code associated with the campaign, but that connection remains speculative and does not constitute a definitive attribution. What is confirmed by multiple reports is that the logistics sector has been repeatedly attacked by related campaigns (including documented campaigns by security companies such as Proofpoint and research groups that have described phishing and malware operations aimed at transport and logistics).

What the reader can do now (concrete measures): immediate technical and operational measures should be implemented for users and companies in the logistics sector.

Actions for mobile users: not install applications outside Google Play unless absolutely necessary; disable the option of "install applications from unknown sources"; review and revoke SMS permissions, calls and notifications for unreliable apps; check if the device screen shows absence of launcher or missing icons (hidden app signal); install and keep Google Play Protect enabled; if you suspect infection, isolate the network device, perform evidence backup and consider a factory re-establishment after exporting important data.

Actions for IT and safety in companies: block at perimeter level the known IP 69.55.61.82 and the URLs / hosts indicated by the reports; implement IDS / IPS rules to detect HTTP POSTs to routes such as / api / v1 / sms / report and periodic beats from mobile devices; restrict the ability of sideload in corporate devices through MDM policies; force MFA based on applications (not on SMS) for critical access; audit and monitor redirections of calls in fleets and report unusual changes; deploy behavior detection on mobile endpoints and correlate events to sensitive access to these platforms.

Additional operational recommendations: train drivers and equipment in phishing recognition (including BEC and speed-phishing that mimic industry platforms), require the use of TOTP authenticators or FIDO keys for corporate accounts, and maintain offline verification procedures for critical changes in delivery or billing instructions. If commitment is confirmed, preserve network logs, C2 contacts and APK metadata for forensic analysis.

Corp MDM: Android spyware points to the logistics sector, steals SMS and miscalls
Image generated with IA.

Limitations and uncertainties: some elements remain open: there is no definitive attribution of the actor; the total scope of victims has not been published; and the operational effectiveness of malware in real environments may be mitigated by the detected bugs. Details of the relationship between this campaign and other activity sets (e.g., phishing platforms such as Global Profit or previous campaigns cited by researchers) are consistent with a criminal pattern aimed at the sector, but the tacit link between operations requires more evidence.

To deepen and verify: the technical reader can consult the documentation of Android permissions and good practices to block facilities outside the official store in https: / / develop.android.com / guide / topics / permissions / overview and recommendations to control installation of apps of unknown origins in https: / / support.google.com / googleplay / answer / 10695538? hl = en. The Have I Been Squatted project maintains public information and analysis about campaigns that use fake sites to distribute malware in https: / / habebeenschatted.com /.

In short, although Corp MDM is not the most sophisticated spyware seen, it adopts an effective strategy for its goal: to operate in silence on devices of the logistics ecosystem, to intercept critical communications and to give the remote operator levers to manipulate calls and receive real-time delivery information. Prevention - avoiding sideloading, tightening permits, and migrating sensitive real estate outside the SMS - remains the most effective defence for organisations and workers in the sector.

Coverage

Related

More news on the same subject.