The global logistics and transportation sector has emerged as the target of a sophisticated new malicious cyber campaign that distributes a specialized Android spyware implant codenamed Corp MDM.

According to new findings from threat intelligence researchers at Have I Been Squatted, the ongoing operation relies on meticulously crafted fake Google Play Store pages branded after prominent logistics entities, including CEVA and TKW Logistics. These fraudulent storefronts are utilized to trick unsuspecting industry professionals into downloading a malicious Android Package Kit (APK) file. Disguised cleverly as a legitimate system service under the package name "com.corp.mdm," the application lays the groundwork for persistent device surveillance once sideloaded onto a target’s smartphone or mobile device.

Security researcher Ben Folland described Corp MDM as a "compact surveillance implant designed to exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service." Unlike sprawling commercial stalkerware suites or advanced state-sponsored espionage tools, this particular strain of malware is remarkably narrow by design. It deliberately lacks many of the broader, feature-rich spyware capabilities traditionally observed in commercial Android threats.

Intriguingly, technical analysis of the codebase indicates that the threat actor behind the campaign likely utilized artificial intelligence (AI) tools during the application’s development phase. Researchers noted the presence of distinct bugs and structural anomalies within the code that actively interfere with and limit the malware’s overall capabilities, suggesting automated generation or human-AI collaboration during production.

Infrastructure and Multi-Pronged Tactic Targeting Supply Chains

The Android spyware deployment is not an isolated vector; rather, it forms a critical component of a much broader, coordinated campaign aimed squarely at the logistics and supply chain sector. This wider cybercriminal effort concurrently employs credential-phishing lures and Windows-based malware payloads to compromise enterprise environments across multiple operating systems.

Investigations into the malicious infrastructure revealed that both the Android APKs and the accompanying Windows-based threats share a hard-coded IP address ("69.55.61[.]82"). This specific server infrastructure functions as the centralized command-and-control (C2) node, while simultaneously hosting credential-phishing landing pages designed to harvest corporate logins from logistics personnel.

Once an employee sideloads and installs the malicious APK, the app immediately prompts the user for broad device permissions, specifically targeting SMS handling, telephony operations, and system notifications. Granting these permissions grants the malware the operational freedom required to intercept incoming text messages, enable unauthorized call forwarding, and display deceptive notifications that mask its background activities. Furthermore, the malicious application systematically removes its standard launcher icon from the device interface to ensure it remains hidden from the user, while establishing a resilient foreground service to maintain uninterrupted execution.

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

Following successful installation, the malware initiates a persistent communication loop with the C2 infrastructure. It registers a unique Android identifier with the remote server, continuously transmitting heartbeat telemetry signals every 30 seconds. Simultaneously, the application polls the server for new instructions on a rapid, recurring schedule, awaiting commands from the threat operators.

Attacker-controlled infrastructure tied to the campaign has also been found hosting a password-protected administrative panel for Corp MDM on port 3456. This web-based interface grants the remote operators the ability to fully commandeer infected mobile devices and issue specific operational commands on demand, establishing granular control over the compromised endpoint.

High-Value Interception via Cleartext Traffic

Despite its narrow design and development flaws, Corp MDM possesses mechanisms capable of extracting highly sensitive data from victims. Notably, the malware’s SMS-stealing functionality is intentionally scoped to intercept new inbound messages arriving only after the necessary permissions have been granted by the user. It does not retroactively exfiltrate historical contents residing within the device’s existing SMS inbox.

Even with this limitation, security analysts emphasize that intercepting live incoming traffic is more than sufficient to expose critical, high-value corporate and personal data.

"That limited collection path is sufficient to expose high-value content," Ben Folland explained. "SMS remains common for one-time passcodes, password resets, account recovery, transaction notifications, and dispatch or delivery updates. The sender, full body, and timestamp all leave the device over cleartext HTTP."

Because the telemetry and data exfiltration occur over unencrypted cleartext HTTP connections, any network observer positioned along the path can theoretically inspect or manipulate the transmitted data stream, further compounding the security risks for affected organizations.

While the exact identity of the threat actors behind the Corp MDM operation remains officially unconfirmed, researchers at Have I Been Squatted point to strong indicators suggesting an Armenian or Russian nexus. This assessment is supported by localized linguistic artifacts discovered within the administrative panel’s user interface and underlying source code tied to the broader campaign infrastructure.

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

A Persistent Threat to Global Freight and Logistics

The emergence of Corp MDM underscores a growing and persistent trend among cybercrime syndicates targeting the global transportation, trucking, and freight verticals for financial gain. The logistics sector—characterized by fast-paced communications, dispersed workforces, and heavy reliance on mobile devices and digital freight-matching platforms—has increasingly become a lucrative hunting ground for financially motivated threat actors.

This recent activity builds upon a documented pattern of cyberattacks directed at the supply chain industry over recent months. In November 2025, security firm Proofpoint detailed a widespread campaign that compromised trucking and logistics enterprises by deploying remote monitoring and management (RMM) software specifically for financial extortion and lucrative cargo theft operations.

Earlier in February, independent threat intelligence researchers from Ctrl-Alt-Intel and Have I Been Squatted published detailed findings regarding a prominent threat cluster codenamed Diesel Vortex. This group specifically singled out freight and logistics entities across the United States and Europe, compromising major platforms and operational networks including DAT Truckstop, TIMOCOM, Teleroute, Penske Logistics, Girteka, and Electronic Funds Source (EFS).

Further compounding these risks, investigations have uncovered a Russian-Armenian threat operation utilizing a sophisticated phishing-as-a-service (PhaaS) platform known as Global Profit, also tracked as MC Profit Always. Specifically engineered to target the freight and logistics sector through deceptive communications, this platform successfully harvested more than 1,600 unique corporate login credentials between September 2025 and February 2026.

Security researchers emphasize that these operations reflect a highly organized, professionalized criminal service rather than the work of isolated opportunistic hackers. These structured cybercrime rings actively employ targeted spear-phishing, voice phishing, and social engineering techniques—often infiltrating professional trucking and logistics groups on messaging applications like Telegram.

By successfully impersonating the legitimate digital platforms that industry workers rely on for daily operations, attackers have demonstrated the capability to intercept login credentials and multi-factor authentication codes in real time. Armed with this unauthorized access, malicious operators have gone on to divert shipments through invoice manipulation and double-brokering schemes, access sensitive personal records, and siphon funds directly from industry participants.

Leave a Reply

Your email address will not be published. Required fields are marked *