VYPR
malwarePublished Sep 24, 2026· 1 source

New Corp MDM Spyware Targets Logistics Firms with SMS Theft and Call Redirection

A new Android spyware, Corp MDM, is targeting the logistics sector by impersonating logistics companies on fake Google Play pages to steal SMS messages and redirect calls.

A sophisticated new Android spyware campaign, identified as Corp MDM, is specifically targeting the logistics sector. Threat actors are employing deceptive tactics, creating fake Google Play pages that impersonate well-known logistics companies such as CEVA and TKW. These malicious pages serve as a distribution point for an Android Package Kit (APK) file disguised as a legitimate system service, bearing the package name "com.corp.mdm".

Security researchers describe Corp MDM as a "compact surveillance implant" designed with a focused set of capabilities. Its primary functions include exfiltrating newly received SMS messages, diverting phone calls, and maintaining a hidden foreground service to ensure persistent operation. Notably, the spyware lacks the broader range of functions often seen in commercial spyware, leading to speculation that the threat actors may have utilized artificial intelligence (AI) during its development, potentially explaining some of the bugs observed that interfere with its functionality.

The Corp MDM campaign appears to be part of a larger, coordinated effort targeting the logistics industry. This broader campaign also involves credential phishing schemes and the distribution of Windows-based malware. The command-and-control (C2) infrastructure used by the malicious actors, identified by a hard-coded IP address "69.55.61[.]82", serves a dual purpose: hosting the C2 communications for the Android spyware and delivering the phishing lures and Windows malware.

Upon installation, the Corp MDM app requests critical permissions, including access to SMS messages, telephony functions, and notifications. This allows the spyware to intercept incoming SMS messages, reroute phone calls, and display notifications. To evade detection and maintain stealth, the malicious app removes its standard launcher icon while ensuring its background service remains active.

The spyware communicates with its C2 server by registering a unique Android identifier and sending regular heartbeat telemetry. It also polls for commands from the threat actor at frequent intervals. The communication endpoints include specific API calls for device registration, heartbeat messages, command retrieval, command result reporting, and SMS reporting, transmitting sender details, message body, and timestamps over cleartext HTTP.

An administrator panel, protected by a password and hosted on port 3456, allows the threat actor to manage infected devices and issue commands. Supported commands include basic functions like pinging the device, enabling or disabling call forwarding to a specified number, synchronizing SMS messages, and self-destructing the implant. While the panel supports commands for device locking and location retrieval, the malware itself does not currently implement these features.

Corp MDM's SMS exfiltration capability is limited to new inbound messages received after the necessary permissions are granted, meaning it does not retroactively steal the entire SMS inbox. However, this focused collection is sufficient to expose sensitive information, as SMS messages are commonly used for one-time passcodes, password resets, account recovery, and transaction notifications. The cleartext transmission of sender, body, and timestamp poses a significant risk.

While the identity of the threat actors remains unclear, analysis of localized artifacts within the admin panel's user interface and source code suggests a potential Armenian or Russian nexus. This incident follows a pattern of increased targeting of the logistics sector, with previous campaigns involving remote monitoring and management (RMM) software for financial gain and cargo theft, as well as the Diesel Vortex threat cluster that targeted freight and logistics entities in the U.S. and Europe.

Synthesized by Vypr AI