A new cyber threat targeting the logistics sector has emerged, employing Android spyware named Corp MDM to distribute malicious software. The Have I Been Squatted campaign employs deceptive Google Play pages masquerading as CEVA and TKW Logistics to distribute an Android Package Kit (APK) disguised as a system service. The installed app bears the package name "com.corp.mdm."
This APK is a "compact surveillance implant" designed to intercept newly received SMS messages, divert calls, and maintain a hidden foreground service, as revealed by security researcher Ben Folland.
Malicious packages are distributed via fake Google Play Store pages, including "playgoogle.logisticstkwcargo[. ]com" and "playgoogle.ceva-app[.]help." Both artifacts use a hardcoded IP address ("69.55.61[.
]82") for command-and-control (C2), as well as for hosting credential-phishing lures and serving additional Windows malware targeting the logistics sector. After sideloading and installation, the malicious app demands SMS, telephony, and notification permissions, enabling it to intercept incoming messages, enable call forwarding, and display notifications. In the subsequent phase, it registers an Android identifier with the C2 server, sending heartbeat telemetry every 30 seconds and polling for commands every second - /api/v1/devices/register, /api/v1/devices/heartbeat, /api/v1/devices/{ANDROID_ID}/commands, and /api/v1/commands/result. To obtain the device's location.
The activity's origins are currently unknown, but HIBP believes it may be linked to an Armenian or Russian group, based on localized artifacts in the panel user interface and associated source code.









![Top 10 Best Decentralized Identity Solutions in 2026 [Ranked & Scored]](http://cybersecuritynews.com/wp-content/uploads/2026/09/Best-Decentralized-Identity-Solutions-1.webp)

