Corp MDM Android Spyware Targets Logistics Firms With SMS Theft and Call Forwarding

Android mobile-security monitoring for a logistics organization

Logistics organizations are being targeted with an Android spyware application called Corp MDM that is distributed through fake Google Play pages and disguised as a corporate system service. Research from Have I Been Squatted shows the implant can exfiltrate newly received SMS messages, activate call forwarding and maintain background communications with attacker infrastructure.

Fake enterprise branding supports installation

The malicious application is delivered from pages that imitate logistics brands rather than the official Play Store. After sideloading, it requests permissions for SMS, telephone and notifications, removes its launcher icon and registers the device with a command-and-control service. The observed implant collects new incoming messages rather than a full historical inbox, but that can still expose one-time passcodes, recovery messages and dispatch information.

The associated control panel includes commands for enabling or disabling unconditional call forwarding. Researchers also found options that were displayed in the panel but not fully implemented by the malware, a distinction that matters when assessing actual capability.

Mobile controls should include distribution provenance

Enterprises should restrict sideloading, verify package origin, monitor device-administration permissions and investigate branded download pages outside approved stores. Mobile-device management is useful only when enrollment is genuine; attackers deliberately borrow enterprise-management language to make intrusive permissions appear routine.

The campaign intersects with Cyber-Physical Security because mobile credentials can expose operational accounts and shipment data. Response teams should review affected telephone settings, revoke exposed sessions and examine related Windows or phishing activity rather than treating the Android implant as an isolated event.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *