EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 70/100

Un nuovo malware Android, Corp MDM, è stato distribuito attraverso pagine finte di Google Play, mirando a aziende logistici. Il malware intercetta SMS, reindirizza chiamate e comunica con un server C2. Non è stato confermato un sfruttamento attivo in rete. Una patch non è stata indicata.

Why it matters

Le PMI logistici sono a rischio di furto di dati sensibili e intercettazione di comunicazioni. La distribuzione tramite Google Play rende il malware accessibile a qualsiasi dispositivo Android non protetto. L'attacco potrebbe compromettere la sicurezza operativa e finanziaria.

Potential operational benefits

  • Riduzione della superficie esposta a malware Android
  • Miglioramento del controllo sugli accessi e le installazioni di applicazioni
  • Rilevamento precoce di attività maliziose
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsFirewall NGFW / IPSMFA / IdentitàMonitoraggio / SIEMPatch managementSegmentazione di rete
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm" Corp MDM

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
24/09/2026 14:05
MITRE ATT&CK
T1190, T1078, T1486
Open the original source