Author: Katie Boquetti | Editorial: Craig Taylor
We’ve known for a while here at CyberHoot that AI-based coding (sometimes called vibe coding) was going to open more doors for hacking than we wanted opened. This Corp MDM malware appears to have been coded using AI by attackers given the number of bugs found in the final product. The use of AI coding tools implies one of many possibilities: the hackers were rushed with little time for testing, or they were not technical enough to test properly, or perhaps they were new to coding in general (possibly vibe coding). While what led to the bugs is uncertain, what is clear is the attackers’ specific goal of targeting logistics companies to steal text messages (including SMS MFA codes), forward phone calls and compromise devices. That stolen data can help attackers steal your cargo, your money, and your good name. These attackers also hosted fake login webpages which would allow users to enter authenticator codes into leading to their theft. That’s yet another reason why I’m so enamored with a more resilient MFA method called passkeys, as those would be of no value on fake website login pages.
This week’s blog article contains simple, clear messages you can share with your team: never sideload apps, adopt resilient multi-factor authentication methods, and teach staff how to report potential attacks like this one quickly so the alarm can be raised and details shared with all staff members.
— Craig
Logistics teams keep trucks, ships, and shipments moving on tight schedules, and a new Android spyware campaign is trying to take advantage of those busy days. Security researchers at Have I Been Squatted found a malicious app called Corp MDM, which pretends to be company device management software. Once installed via sideloading, it copies new text messages and forwards phone calls to criminals. The good news is a few simple habits stop this attack before it starts, and you do not need a big security budget to put them in place.
The criminals built fake Google Play pages using the names and branding of two real logistics companies, CEVA Logistics and TKW Logistics. Employees who visit these pages see an app called Corp MDM, named to look like the device management software many companies ask staff to install on work phones. Since the file does not come from the real Google Play Store, the victim has to install it by hand, a process called sideloading (many red flags here). After installation, the app asks for permission to read text messages, manage phone calls, and show notifications. It then hides its icon from the home screen and keeps running in the background. Tip: Real company apps arrive through official app stores or your IT contact, so a link to a special download page is your cue to pause and ask before installing anything.
Corp MDM checks in with the attacker’s server every 30 seconds and waits for orders. The app sends every new incoming text to the criminal, including who sent it, what it says, and when it arrived. It turns on call forwarding, so all incoming calls ring on the attacker’s phone instead of yours. It also deletes itself on command to remove evidence. One piece of good news is the malware only grabs texts arriving after installation, so your older messages stay private. Researchers also found multiple bugs in the code and believe the malware author likely used AI tools to write it. Even criminals ship buggy software. Their clumsy code still works well enough to steal messages, so any app asking to read your texts and manage your calls deserves a second look before you tap Allow.
Many banks, email providers, and business apps still send one time passcodes by text. Password resets and account recovery codes often arrive the same way. When a criminal reads those messages, a stolen password turns into a full account takeover. Call forwarding adds another path, since some services verify you with an automated phone call. In logistics, texts also carry dispatch and delivery details, which help criminals redirect invoices or steal cargo. Tip: Text message codes beat having no second step at login, but switching to an authenticator app or passkey use gives you stronger protection against tricks like this one.
The same server behind Corp MDM also hosts fake login pages and Windows malware aimed at the logistics industry. Researchers see signs of an Armenian or Russian connection, though nobody has confirmed who runs the operation. In late 2025, Proofpoint reported criminals installing remote access tools at trucking companies to steal cargo. Earlier in 2026, researchers described a group called Diesel Vortex, which used a phishing service called MC Profit Always to steal more than 1,600 logins from the sector. The goal each time was money, through redirected invoices, fake brokers, and stolen freight. The logistics industry attracts criminals because logistics work moves money and goods, and knowing this helps teams spot tricks sooner.
Start by training your team where real company apps come from. A one line message such as “We will never send you a link to install work software” sets a clear rule everyone remembers. Next, turn off installs from unknown sources on work Android phones, which most phones list under Security or Apps settings. If you already use a mobile device management tool, check for a setting to block sideload installs for everyone. Then move your most important accounts, starting with email and banking, from text message codes to passkeys (or if passkeys are unavailable, to an authenticator app) or hardware token. Finally, ask your mobile carrier how to confirm call forwarding is disabled, and review app permissions once a month for anything reading texts or managing calls without a clear reason.
Pick one habit from this article and try it this week. Share the official apps only rule with your team at your next meeting, or move your company’s email account access onto (1) passkeys or (2) authenticator apps. Small steps add up, and every safer choice today puts you ahead of yesterday. CyberHoot’s short, friendly training videos and phishing simulations help your whole team build these habits without fear or shame. Laugh, learn, and Hoot Up!
Q: What is Corp MDM?
A: Corp MDM is Android spyware disguised as company device management software. It copies new text messages and forwards phone calls to criminals.
Q: Who are the attackers targeting?
A: Employees at logistics and freight companies. The fake download pages use the names of CEVA Logistics and TKW Logistics.
Q: Does Corp MDM appear in the real Google Play Store?
A: No. Criminals host it on fake Google Play pages, and victims must install it by hand. Use a real MDM solution to block sideloading installs to stop this attack. No MDM? Tell staff to tap Cancel on any ‘Install unknown apps’ prompt.
Q: Why do criminals want my text messages?
A: Many services send login codes, password resets, and recovery codes by text. Reading those messages lets a criminal take over accounts protected by those codes.
Q: How do I check whether my phone is infected?
A: Look for an app you do not recognize with permission to read texts and manage calls, a background notification you never set up, or calls which stop reaching you. Note: this app hides its icon, so check Settings > Apps. If something looks wrong, tell your IT contact, remove the app, turn off call-forwarding (on most carriers, dialing *#21# checks for call forwarding and ##21# turns it off, but ask your carrier to be certain), and change passwords for accounts using text message codes. Reporting early protects your whole team, and there is no shame in asking for help.
The Hacker News: Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.
Author: Katie Boquetti | Editorial: Craig Taylor Editorial by Craig Taylor: We've known for a while here...
Read more
Author: Katie Boquetti | Editorial: Craig Taylor Editorial by Craig Taylor: I remember the early days of...
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.
