Corp MDM Spyware Targets Logistics Firms, Steals SMS and Redirects Calls
What Happened — A new Android spyware codenamed Corp MDM is being distributed through counterfeit Google Play pages that impersonate logistics providers CEVA and TKW Logistics. The malicious APK (package com.corp.mdm) masquerades as a system service, installs on employee devices, exfiltrates SMS messages and redirects voice calls to attacker‑controlled numbers. The campaign is focused on companies in the transportation and logistics sector.
Why It Matters for Trust & Control Assurance
- Highlights the need for continuous monitoring of mobile‑device‑management (MDM) controls and evidence of app‑whitelisting.
- Demonstrates why documented access‑control policies and employee awareness are essential to prevent unauthorized data exfiltration.
- Aligns with the control objective of managing third‑party software and device access, a key pillar of our Access Controls capability.
Who Is Affected
- Transportation & logistics firms that allow Android devices for field operations.
Recommended Actions
- Enforce strict MDM policies that whitelist only approved applications.
- Require multi‑factor authentication for device enrollment and enforce encryption at rest.
- Conduct targeted security‑awareness training on fake‑app phishing tactics.
- Collect and retain evidence of device compliance for audit readiness.
Source: The Hacker News
Technical Notes
- Attack vector: Phishing via fake Google Play listings.
- Payload: Android Package Kit (APK) named
com.corp.mdm. - Capabilities: SMS harvesting, call redirection, potential credential capture.
Source: Same as above