# Android spyware campaign targets logistics firms through fake app pages

_Published Thursday, September 24, 2026 at 9:07 AM EDT · Security · Latest · Tier 2 — Notable_

![Android spyware campaign targets logistics firms through fake app pages — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhitRqKj3-JlcQ69xxlsxJs80aq7MNxgAc_VrV-TCrHGTVEwdWKIdvAiwB4szXMT3cRKpkzCRVObZxAO47CLl3JWLRerxVSITKy9xorsP-XY212M07JzDkZ7VXOA-r0maycB0jMv0r5Kl3q0VgrxpoeYfHJ_gkeXbzXLKz_3gAhDGy1ML06lfta_5w8u_Xo/s1700-nu-rw-lo-l85-e365/1000110893.jpg)

A campaign targeting logistics firms is distributing Android spyware through fake Google Play pages branded as CEVA and TKW Logistics, The Hacker News reported, citing research by Have I Been Squatted. The app, called Corp MDM, disguises itself as a system service and asks for access to text messages, calls and notifications.

Once installed, it can send newly received text messages to an attacker-controlled server and enable call forwarding. The same infrastructure hosts credential-phishing pages and additional Windows malware aimed at the sector. Corp MDM cannot retrieve messages received before its permissions were granted, and the researchers have not identified the operator.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html)

---
Canonical: https://techandbusiness.org/newswire/Cv5_pxZXi-KM8K-7axzFK-
Published: 2026-09-24T13:07:44.376Z
Story chronology: 2026-09-24T12:05:27.000Z
Retrieved: 2026-09-24T15:08:55.546Z
Publisher: Tech & Business (techandbusiness.org)
