Corp MDM Spyware Exploits Logistics Firms to Intercept SMS and Redirect Calls
A new Android spyware campaign, Corp MDM, targets logistics firms by intercepting SMS and redirecting calls through fake Google Play pages, with suspected ties to Armenian or Russian threat actors. The malware uses a command-and-control infrastructure to exfiltrate data and execute remote commands, highlighting vulnerabilities in sector-specific cybersecurity.
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM.
According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm"
Corp MDM
*** END OF TRANSMISSION ***