Android Spyware Disguised as MDM App Hits Logistics Companies

A new Android spyware campaign dubbed Corp MDM is targeting logistics firms. Attackers use fake Google Play pages for CEVA and TKW Logistics to distribute a malicious APK disguised as a system service. The app steals SMS messages and redirects calls.
The campaign exploits trust in mobile device management tools, a common enterprise necessity, to slip past user suspicion. By cloning Google Play store pages for established logistics brands, the attackers create a convincing front for their malicious download, preying on employees who may expect to install work-related software.
Once active, the spyware operates with elevated system permissions, allowing it to intercept SMS traffic and reroute phone calls. This level of access could compromise two-factor authentication codes and disrupt critical communications within the supply chain, making the logistics sector a particularly vulnerable target for this type of intrusion.
This campaign could disrupt operations at targeted firms by intercepting time-sensitive delivery confirmations and security codes. Employees handling logistics data may face credential theft, while clients could see shipments delayed or misrouted due to compromised communications. The broader logistics industry may need to reassess mobile device policies, as the attack demonstrates how trusted enterprise tools can be weaponized, potentially eroding confidence in mobile-first supply chain management.