Fake CEVA Apps Are Quietly Hijacking Android Phones

·
Listen to this article~4 min
Fake CEVA Apps Are Quietly Hijacking Android Phones

A new Android spyware called Corp MDM is hiding behind fake CEVA and TKW Logistics pages. It steals your texts, redirects calls, and turns your phone into a puppet. Here's how to spot it.

The logistics world just got a nasty wake-up call. A new Android spyware called Corp MDM is spreading through fake Google Play pages that look like they belong to CEVA and TKW Logistics — two names you'd normally trust if you work in shipping or freight. According to a report from Have I Been Squatted, the attackers are distributing an Android Package Kit (APK) file disguised as a harmless system service. Once installed, the app — hiding behind the package name "com.corp.mdm" — burrows deep into the phone. ### What exactly does Corp MDM do? This isn't your average pop-up ad malware. Corp MDM is designed to be a silent observer. Here's what it's capable of: - **Steals incoming SMS messages** — including one-time passcodes from banks and other services. - **Redirects phone calls** to numbers controlled by the attackers. - **Runs in the background** without a visible icon, making it hard to spot. - **Disguises itself as a system update** so users don't get suspicious. In other words, it turns your phone into a puppet. And if you're using that phone for work — checking shipment tracking, coordinating drivers, confirming deliveries — the damage can go way beyond a single device. > "The logistics sector is a goldmine for attackers because it's full of time-sensitive communication and third-party apps," one security researcher told us. "One compromised phone can lead to a fake delivery notice that spreads to an entire network." ### Why logistics firms are the perfect target Think about how logistics operates. Dispatchers, drivers, warehouse managers — they're constantly installing apps to track packages, scan barcodes, and communicate with partners. When a fake "CEVA" app shows up in a search result, it's easy to click install without a second thought. And that's exactly what the attackers are counting on. They're not hacking into servers. They're tricking people. A fake Google Play page that looks legitimate is often all it takes. ### How to protect yourself and your team You don't need a security degree to stay safe. A few simple habits go a long way: - **Only install apps from official sources** — and double-check the developer name. If CEVA or TKW Logistics hasn't announced an app, it probably doesn't exist. - **Watch for sideloaded APKs** — if someone sends you a link to download an app outside the Play Store, treat it like a suspicious package. - **Check your phone's app list** for anything called "com.corp.mdm" or similar generic system names you don't recognize. - **Use a mobile security tool** that can scan for known spyware signatures. If you think you've already installed it, back up your important data, factory reset the phone, and change your passwords — especially for banking and email. ### The bigger picture This campaign isn't just about one spyware strain. It's a reminder that the logistics industry — with its constant flow of packages, messages, and deadlines — is a prime target for social engineering. The bad guys don't need to break down the door when they can just knock politely and pretend to be your shipping partner. Stay skeptical. Verify before you install. And if something feels off about an app, trust that feeling. Your phone — and your supply chain — will thank you.