CONNECT WITH US
Cyber Security

Cyber Security

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

The Hacker News logo

Published on

Add as a preferred source on Google
Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM.

According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm"

Corp MDM is a "compact surveillance implant designed to exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service," security researcher Ben Folland said.

The malware has been described as narrow by design, lacking in spyware functions typically observed in commercial Android spyware. It's suspected that the threat actor behind the campaign used artificial intelligence (AI) during the development phase, given the presence of bugs that interfere with its capabilities.

In addition, the activity is said to be part of a broader campaign targeting the logistics sector using credential phishing and Windows-based malware.

The malicious packages are distributed via bogus Google Play Store pages such as below -

Both the artifacts use a hard-coded IP address ("69.55.61[.]82") for command-and-control (C2), as well as for hosting credential-phishing lures and serving additional Windows malware targeting the logistics sector.

Once sideloaded and installed, the malicious app requests SMS, telephony, and notification permissions, allowing it to intercept incoming SMS messages, enable call forwarding, and display notifications. The malware-laced app also removes its normal launcher, while ensuring background execution.

In the next stage, it registers an Android identifier with the C2 server, sends heartbeat telemetry every 30 seconds, and repeatedly polls for commands every seconds -


Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We TheMorningPulse.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It's possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.