Corp MDM: Android spyware that steals texts and diverts calls at logistics companies
Researcher Ben Folland of Have I Been Squatted has uncovered a campaign targeting the logistics sector that distributes Android spyware called Corp MDM. The attackers create fake Google Play pages branded as CEVA Logistics and TKW Logistics so the victim downloads the malicious app, which poses as a corporate device management tool. The campaign is rounded out with credential phishing emails and Windows malware.
Once installed, the app requests SMS, call and notification permissions, stays hidden in the background and pings the attacker every 30 seconds. Its main job is to intercept new text messages and turn on call forwarding to numbers controlled by the criminals. That lets them grab one-time codes, password reset links and transaction alerts sent by text, so they can bypass SMS-based two-step verification.
Tip from Soporte Informático 360
Only install apps from the official store and never from links received by email or message, even if they seem to come from your company or a supplier. Whenever you can, replace SMS codes with an authenticator app or a security key, and check whether your phone has any call forwarding turned on that you don’t recognise.
Source: The Hacker News. Summary prepared by our team for informational purposes.
Computer repair for home users
We repair desktops, laptops and mini PCs that won’t start, shut down, overheat or run slowly.