Android Spyware Corp MDM Hijacks Calls and Texts at Logistics Firms

·
Listen to this article~3 min
Android Spyware Corp MDM Hijacks Calls and Texts at Logistics Firms

A new Android spyware called Corp MDM is targeting logistics companies. It steals SMS messages and redirects calls, all while disguised as a legitimate app from CEVA or TKW Logistics. Here's what you need to know.

### The Sneaky New Spyware Hitting Logistics Companies Imagine you're a logistics manager, juggling shipments and tracking deliveries. You get a notification about a system update from a company you trust, like CEVA or TKW Logistics. You click it, thinking it's routine. But instead, you've just invited a spy into your phone. That's exactly what's happening with a new Android spyware called Corp MDM. According to Have I Been Squatted, this malware is spreading through fake Google Play pages that look like they belong to CEVA and TKW Logistics. These pages trick you into downloading an APK file that pretends to be a system service. Once installed, the app—with the package name "com.corp.mdm"—quietly takes over your device. ### What Exactly Does Corp MDM Do? This isn't your average adware. Corp MDM is designed for espionage. Here's a quick rundown of its nasty tricks: - **Steals new SMS messages**: Every text you receive, from two-factor authentication codes to private conversations, gets sent to the attackers. - **Redirects calls**: Incoming calls are silently forwarded to the bad guys, so you never even know someone tried to reach you. - **Harvests data**: It can also grab contacts, call logs, and other sensitive info, giving cybercriminals a full picture of your digital life. And because it's disguised as a legitimate app, it can fly under the radar for a long time. ### Why Logistics Firms Are a Prime Target Logistics companies are the backbone of global trade. They handle valuable shipments, sensitive delivery schedules, and often coordinate with multiple partners. A breach here can lead to stolen goods, disrupted supply chains, and leaked business secrets. That's why attackers are focusing on this sector—it's high-stakes and often has weaker cybersecurity than, say, a bank. ### How to Protect Yourself So, what can you do? First, never download apps from unofficial sources. Even if a page looks like Google Play, double-check the URL. Legitimate companies don't distribute APKs outside the Play Store. Second, keep your device updated and use a reputable mobile security app. Third, if you suddenly stop receiving calls or texts, that's a red flag—check your call forwarding settings immediately. > "In the world of cybersecurity, trust is a vulnerability. Verify everything, especially when it comes to your phone." ### The Bottom Line Corp MDM is a wake-up call. As we rely more on mobile devices for work, the threats evolve. Stay informed, stay skeptical, and protect your data like it's your most valuable shipment.