Security researchers have uncovered a malicious Android campaign aimed at the logistics industry. The spyware, named Corp MDM, is distributed through fake Google Play pages that impersonate two logistics companies, CEVA and TKW Logistics, according to a report from Have I Been Squatted.
The campaign relies on these fraudulent pages to trick users into installing a malicious Android Package Kit (APK). Once installed, the spyware can intercept new SMS messages and redirect calls, giving attackers access to sensitive communications within targeted organisations.
The discovery highlights how threat actors are abusing trusted brand names to distribute mobile malware. Logistics firms and Android users should be cautious about installing apps from unofficial or lookalike pages, as this campaign demonstrates the potential for data theft through seemingly legitimate channels.