hacker-news · Crawled Sep 24, 2026

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

4 IoCs
Read original article ↗

AI Summary

A malicious Android spyware dubbed Corp MDM is targeting logistics firms by distributing fake Google Play pages impersonating CEVA and TKW Logistics. The malware, delivered as a trojanized APK with package name 'com.corp.mdm', steals newly received SMS messages, redirects calls, and maintains a hidden foreground service. It communicates with a command-and-control server at 69.55.61.82 via HTTP, exfiltrating SMS content and device identifiers while supporting remote commands such as call forwarding and self-destruction. The campaign is suspected to be financially motivated, with links to a Russian-Armenian threat actor operating a phishing-as-a-service platform called Global Profit.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
Domain playgoogle[.]logisticstkwcargo[.]com Details →
Domain playgoogle[.]ceva-app[.]help Details →
IP 69[.]55[.]61[.]82 Details →
Package com.corp.mdm Details →