< Back to all clusters
[TECHNOLOGY] · Portugal · 4 sources

started · updated

Android spyware targets logistics firms and banking users

A new Android spyware campaign, codenamed Corp MDM, is specifically targeting the logistics sector. The malware is distributed through fraudulent Google Play pages that impersonate established brands such as CEVA and TKW Logistics to trick users into manually installing malicious APK files.

Corp MDM is designed to function as a compact surveillance implant. Once installed, it requests permissions for SMS, telephony, and notifications, allowing attackers to exfiltrate new messages, divert calls, and maintain a hidden foreground service. This capability poses a significant risk to professional environments where mobile devices are used for critical operational communications and authentication codes.

In a separate but related trend of mobile threats, the RemControl Android malware-as-a-service (MaaS) platform has been identified targeting users in Europe and Canada. This malware uses malvertising to impersonate the TVTap IPTV application and employs phishing overlays to steal banking credentials. Researchers noted that RemControl may have been developed with the assistance of artificial intelligence, evidenced by the presence of AI-generated assistant responses within its phishing overlays.

Additionally, cybersecurity researchers have observed the DarkMe remote access trojan (RAT) shifting its tactics from using zero-day exploits to simpler phishing emails. This malware targets a wide range of applications, including trading terminals, cryptocurrency wallets, and communication tools, to identify high-value targets.

Entities

Ceva · Google Play · TKW Logistics