The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM.
According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm"
Corp MDM is a "compact surveillance implant designed to exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service," security researcher Ben Folland said.
The malware has been described as narrow by design, lacking in spyware functions typically observed in commercial Android spyware. It's suspected that the threat actor behind the campaign used artificial intelligence (AI) during the development phase, given the presence of bugs that interfere with its capabilities.
In addition, the activity is said to be part of a broader campaign targeting the logistics sector using credential phishing and Windows-based malware.
The malicious packages are distributed via bogus Google Play Store pages such as below -
Both the artifacts use a hard-coded IP address ("69.55.61[.]82") for command-and-control (C2), as well as for hosting credential-phishing lures and serving additional Windows malware targeting the logistics sector.
Once sideloaded and installed, the malicious app requests SMS, telephony, and notification permissions, allowing it to intercept incoming SMS messages, enable call forwarding, and display notifications. The malware-laced app also removes its normal launcher, while ensuring background execution.
In the next stage, it registers an Android identifier with the C2 server, sends heartbeat telemetry every 30 seconds, and repeatedly polls for commands every seconds -
Source link







