The images in this article were generated with artificial intelligence. How we publish
A new operation directed against the logistics sector uses an Android spyware identified as Corp MDM, which is being distributed through fraudulent pages that imitate Google Play and industry brands. Researchers who follow the campaign - including the analyst Ben Folland and the project Have I Been Squatted - have documented APK packages with the name of a "com.corp.mdm" package hosted in sites such as playgoogle.logisticstkwcargo [.] com and playgoogle.ceva-app [.] help, and communicating with a fixed IP address (69.55.61.82) used both for infection control and for hosting phishing and Windows signs.
Confirmed facts: according to the technical analysis published by the researchers, Corp MDM is a compact implant designed for exfilter incoming SMS, redirect calls and stay hidden in background execution. The malware requests SMS permissions, telephony and notifications after installation, removes its icon from the start screen (launcher) to hide and establishes regular communication with a command and control server (C2) using HTTP routes such as / api / v1 / devices / register, / api / v1 / devices / heart beat, / api / v1 / devices / {ANDROID _ ID} / commands and / api / v1 / sms / report. The management panel hosted in the attacking infrastructure listens at port 3456 and provides remote commands - ping, forward _ on, forward _ off, sync _ sms, self _ destroy - that allow, for example, to activate the unconditional diversion of calls to a number controlled by the attacker or to request the sending of newly received SMS.

How it works technically: the documented operating flow is as follows. First, the victim downloads and installs the APK from a page that imitates Google Play (sideloadeo). When granting permits, the application can intercept incoming SMS and send its content (sender, body and time mark) to C2 by using HTTP in clear. The application records an Android identifier on the server, sends periodic beats (every ~ 30 seconds) and consults commands. Call redirection orders are run by GSM codes (e.g., activation of the operator -selected number and cancellation using # # 21 #), and there is a self-deleted order that aims to disable the implant and clean up the app data.
Limitations and anomalies observed: analysts describe Corp MDM as "narrow by design"- lacks many regular capabilities in commercial spyware and only captures SMS received from the moment permits are granted; it does not make a retroactive turn of the SMS mailbox. In addition, the software contains implementation errors that have led to the hypothesis that artificial intelligence was used during its development to accelerate production, which would have introduced bugs that limit its effectiveness. It is also significant that exfiltration is done by HTTP without encryption, which facilitates its detection in networks that inspect outgoing traffic.
Who affects and why it matters: the campaign is directed to the logistics ecosystem - transport operators, parcel companies, drivers and personnel handling notifications by SMS - where single-use codes, shipping confirmations, invoice readdresses or changes in delivery instructions are valuable signs for fraud or cargo theft. The requested permissions allow intercept SMS authentication codes (OTP) and critical notifications, and the call diversion control opens the door to interception of telephone checks or fraudulent coordination with field staff.
Real plausible consequences: with the data extracted and access to telephone communications, a malicious operator can make suplantations (account takeover), financial fraud, redirection of shipments (investment redirection, double-breaking) and coordination to appropriate charges. Although Corp MDM seems less elaborate than other commercial families, its ability to capture sensitive content in real time is sufficient to compromise processes that depend on SMS and calls.
Attribution and context: Have I Been Squated points to signs of an Armenian or Russian nexus in artifacts located in the panel interface and code associated with the campaign, but that connection remains speculative and does not constitute a definitive attribution. What is confirmed by multiple reports is that the logistics sector has been repeatedly attacked by related campaigns (including documented campaigns by security companies such as Proofpoint and research groups that have described phishing and malware operations aimed at transport and logistics).
What the reader can do now (concrete measures): immediate technical and operational measures should be implemented for users and companies in the logistics sector.
Actions for mobile users: not install applications outside Google Play unless absolutely necessary; disable the option of "install applications from unknown sources"; review and revoke SMS permissions, calls and notifications for unreliable apps; check if the device screen shows absence of launcher or missing icons (hidden app signal); install and keep Google Play Protect enabled; if you suspect infection, isolate the network device, perform evidence backup and consider a factory re-establishment after exporting important data.
Actions for IT and safety in companies: block at perimeter level the known IP 69.55.61.82 and the URLs / hosts indicated by the reports; implement IDS / IPS rules to detect HTTP POSTs to routes such as / api / v1 / sms / report and periodic beats from mobile devices; restrict the ability of sideload in corporate devices through MDM policies; force MFA based on applications (not on SMS) for critical access; audit and monitor redirections of calls in fleets and report unusual changes; deploy behavior detection on mobile endpoints and correlate events to sensitive access to these platforms.
Additional operational recommendations: train drivers and equipment in phishing recognition (including BEC and speed-phishing that mimic industry platforms), require the use of TOTP authenticators or FIDO keys for corporate accounts, and maintain offline verification procedures for critical changes in delivery or billing instructions. If commitment is confirmed, preserve network logs, C2 contacts and APK metadata for forensic analysis.

Limitations and uncertainties: some elements remain open: there is no definitive attribution of the actor; the total scope of victims has not been published; and the operational effectiveness of malware in real environments may be mitigated by the detected bugs. Details of the relationship between this campaign and other activity sets (e.g., phishing platforms such as Global Profit or previous campaigns cited by researchers) are consistent with a criminal pattern aimed at the sector, but the tacit link between operations requires more evidence.
To deepen and verify: the technical reader can consult the documentation of Android permissions and good practices to block facilities outside the official store in https: / / develop.android.com / guide / topics / permissions / overview and recommendations to control installation of apps of unknown origins in https: / / support.google.com / googleplay / answer / 10695538? hl = en. The Have I Been Squatted project maintains public information and analysis about campaigns that use fake sites to distribute malware in https: / / habebeenschatted.com /.
In short, although Corp MDM is not the most sophisticated spyware seen, it adopts an effective strategy for its goal: to operate in silence on devices of the logistics ecosystem, to intercept critical communications and to give the remote operator levers to manipulate calls and receive real-time delivery information. Prevention - avoiding sideloading, tightening permits, and migrating sensitive real estate outside the SMS - remains the most effective defence for organisations and workers in the sector.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...