The logistics sector has been targeted by a new malicious cyber campaign distributing an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) that is disguised as a system service. The provided application has the package name “com.corp.mdm.” Corp MDM is a “compact spyware implant designed to extract the content of new incoming SMS messages, divert calls, and maintain a hidden service in the foreground,” said security researcher Ben Folland.
See also: US Transportation and Logistics Companies Victims of Infostealer

The malware has been described as limited by design, lacking the spying features typically seen in commercial Android spyware. It is suspected that the threat actor behind the campaign used artificial intelligence (AI) during the development phase, given the presence of bugs that interfere with its capabilities. Furthermore, the activity is said to be part of a broader campaign targeting the logistics sector using credential phishing and Windows malware. The malicious packages are distributed via fake Google Play Store pages such as:
- playgoogle.logisticstkwcargo[.]com
- playgoogle.ceva-app[.]help
Both artifacts use a hardcoded IP address (“69.55.61[.]82”) for command and control (C2), as well as hosting credential phishing baits and delivering additional Windows malware targeting the logistics sector.
- Once installed, the malicious app requests SMS, telephony, and notification permissions, allowing it to intercept incoming SMS messages, enable call forwarding, and display notifications. The malicious app also removes its normal launcher while ensuring that it runs in the background. In the next stage, it registers an Android ID with the C2 server, sends heartbeat telemetry every 30 seconds, and repeatedly checks for commands every few seconds:
- /api/v1/devices/register, to register the device, along with basic information
- /api/v1/devices/heartbeat, to send a heartbeat message
- /api/v1/devices/{ANDROID_ID}/commands, to receive commands issued by the threat actor
- /api/v1/commands/result, to publish the results of command execution
- /api/v1/sms/report, to transmit the SMS sender, message body, and time of receipt, along with the device ID
The infrastructure controlled by the attacker has been found to host a password-protected Corp MDM admin panel on port 3456 that allows the operator to control the infected devices and send commands.
See also: SideWinder APT targets shipping and logistics companies

The list of supported commands is as follows:
- ping, to return “pong” via the command result endpoint
- forward_on, to issue a call forwarding code without conditions to a number selected by the operator
- forward_off, to request cancellation of the forwarding without conditions with ##21#
- sync_sms, to report the start of the synchronization process without performing data collection
- self_destroy, to disable the implant components, stop the service, and request application data clearing
- get_location (supported by the panel, but not by the malware)
- lock_device (supported by the panel, but not by the malware)
Importantly, Corp MDM's SMS theft functionality is limited to new incoming messages after permission is granted.
It does not recursively extract the contents of the SMS inbox. “This limited collection path is sufficient to expose high-value content,” Folland said. “SMS remains common for one-time codes, password resets, account recovery, transaction notifications, and shipping or delivery updates. The sender, full body, and timestamp leave the device over pure HTTP.” It’s unclear who is behind the operation at this time, but Have I Been Squatted said the activity likely has an Armenian or Russian connection, citing localized artifacts in the panel’s user interface and source code related to the broader campaign.
See also: GigaWiper: New Threat – Disk Wiping, Fake Ransomware and Spyware

This is not the first time that threat actors have targeted the logistics sector. In November 2025, Proofpoint analyzed a campaign that infected trucking and logistics companies.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
