# Android Spyware Campaign Targets Logistics Firms Through Fake Google Play Pages

*Published September 25, 2026*
*Source: [https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html](https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/android-spyware-campaign-targets-logistics-firms-through-fake-google-play-pages) or [see plans](https://www.sec-news.ai/pricing).*

## Article

The logistics industry is under threat from a new cyber campaign deploying Android spyware known as Corp MDM. The malicious software is disguised as a system service and distributed through fake Google Play pages that mimic legitimate brands like CEVA and TKW Logistics. Once installed, the app requests permissions to intercept SMS messages, enable call forwarding, and display notifications, all while removing its launcher to operate undetected in the background. The spyware specifically targets newly received SMS messages, a common medium for one-time passcodes and other sensitive information, and sends the data over an unsecured channel. 

Research by Ben Folland highlights that Corp MDM lacks many of the functions typical of commercial spyware, suggesting potential use of artificial intelligence during its development, which introduced certain bugs. This campaign is part of a larger effort aimed at the logistics sector, incorporating credential phishing and Windows-based malware attacks. The infrastructure supporting this operation includes a command-and-control server that manages infected devices and collects telemetry data every 30 seconds. 

The threat actors behind this campaign are suspected to have connections to Armenia or Russia, as indicated by the language and structures found in their control panels. Previous incidents in the logistics sector, such as those detailed by Proofpoint and other cybersecurity researchers, have shown a history of using remote monitoring tools and phishing techniques to exploit this industry. The campaign's structured nature and financial motivations underscore the persistent risks faced by logistics companies in securing their operations against such sophisticated threats.
