Fake Google Play Pages Push Spyware at Logistics

The Hacker News · Medium sophistication
Last updated September 25, 2026

A real campaign is targeting logistics firms with fake Google Play pages impersonating well-known logistics brands to trick employees into installing an Android spyware app. Once installed, the spyware can steal newly received SMS messages (including one-time passcodes) and enable call forwarding, which can help criminals take over accounts. The same infrastructure is also used for credential-phishing lures and delivering Windows malware aimed at logistics organizations.

How the attack worked

This campaign targets logistics organizations by impersonating trusted brands. Attackers built fake Google Play pages branded as CEVA and TKW Logistics, then directed employees to sideload an Android APK disguised as a system service rather than installing it through the official app store. Once installed, the app requests SMS, telephony, and notification permissions under the guise of normal app functionality.

The malware is designed to exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service. This combination lets attackers intercept one-time passcodes sent over SMS and reroute calls, both of which support account takeover. Notably, the spyware only captures messages received after permissions are granted, not the entire inbox, which can make its activity less obvious to a casual check of message history.

The same infrastructure supporting this spyware also hosts credential-phishing lures and delivers additional Windows malware aimed at the logistics sector, indicating a broader, multi-channel operation rather than an isolated mobile threat.

Why it succeeded

The attack leans on trust in familiar brand names and the Google Play name itself. Field staff, drivers, and dispatchers who are used to installing work-related apps on Android devices may not scrutinize a link claiming to come from a known logistics provider. Because the page is branded to look like an official app listing, the sideloading step, normally a red flag, can be overlooked in a fast-paced operational environment.

A related part of this ecosystem uses phishing pages that impersonate legitimate logistics platforms employees already use daily. By intercepting logins and multi-factor authentication codes in real time, attackers can bypass the added protection MFA is meant to provide.

What to watch for

  • Links directing you to install an app from a website rather than the official app store
  • Any Android app requesting SMS, telephony, or notification permissions that doesn't match its stated purpose
  • Unexpected sign-in prompts for logistics platforms, especially those framed as urgent shipment or invoice updates
  • Requests to share a multi-factor authentication code outside your normal login flow

Building resistance

Organizations in transportation and warehousing should reinforce that mobile apps are only installed through official app stores or an approved internal process, never through a link in a message or email claiming to be a Play Store page. Teams should also be reminded that legitimate platforms will never ask them to read back or forward an MFA code, and that unexpected shipment or invoice changes should be verified through known, trusted contact channels rather than the link or message that raised the request. Building this habit across dispatch, operations, and field staff reduces the chance that a convincing brand impersonation leads to a real compromise (see attack.mitre.org for technique T1204.001).

Key findings

  • Attackers used "fake Google Play pages branded as CEVA and TKW Logistics" to distribute an Android APK posing as a system service (package: "com.corp.mdm").
  • The spyware is designed to "exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service," enabling interception of one-time passcodes and call forwarding.
  • The same infrastructure ("69.55.61[.]82") was used for command-and-control and also "hosting credential-phishing lures and serving additional Windows malware targeting the logistics sector."
  • Corp MDM only steals SMS received after permissions are granted: "limited to new inbound messages after the permission is granted" (not the full inbox).
  • A broader, logistics-focused criminal ecosystem is described, including phishing-as-a-service that used impersonation of legitimate logistics platforms and included "spear-phishing and voice phishing techniques" targeting logistics Telegram groups.

Who’s being targeted

  • Commonly targeted roles: Operations/Dispatch, Drivers/Field staff, Finance/AP, IT/Helpdesk, Logistics coordinators.
  • Affected industries: Logistics, Freight / Trucking, Transportation and Warehousing.
  • Attack channels: website.
  • Impersonated: Google Play / logistics brand (CEVA or TKW Logistics), Legitimate logistics platforms used daily by targets.

Red flags to watch for

  • App is installed from a website (sideloaded), not the real Play Store
  • Brand domain looks unusual (e.g., not an official company domain)
  • App requests SMS/telephony permissions that don't match a normal logistics app update
  • Unexpected login request or urgent 'shipment/invoice' prompt
  • Login page hosted on unfamiliar domain/IP infrastructure
  • Any request to share MFA codes outside normal authenticator flow
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do attackers deliver the spyware to logistics employees?

They use fake Google Play pages branded as real logistics companies like CEVA and TKW Logistics to distribute an Android APK file disguised as a system service, which is sideloaded rather than installed from the official app store.

What can the spyware do once installed?

It requests SMS, telephony, and notification permissions, allowing it to exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service, which can be used to intercept one-time passcodes.

Does the spyware read a victim's entire text message history?

No, the malware is limited to new inbound messages after the permission is granted, not the full inbox.

Is this campaign only about mobile spyware?

No, the same infrastructure also hosts credential-phishing lures and delivers additional Windows malware targeting the logistics sector.

Read the video transcript

Imagine you’re on your work phone and see a “Google Play” page for CEVA or TKW Logistics telling you: install this required Android service update. You tap install, it sideloads an app called com.corp.mdm, and suddenly it wants SMS, phone, and notification access. That’s spyware built to grab new text messages, including one-time passcodes, and even divert calls, using the same 69.55.61.82 setup that also runs fake login pages for our logistics platforms. Here’s the twist: it only needs new texts after you tap Allow. That’s enough to catch the next MFA code you expect, while a fake shipment or invoice login page on that same 69.55.61.82 site tricks you into entering your password and then reading out or approving that code. If you ever get a link to a “Google Play” page for a logistics app, stop, open the real Play Store yourself, search the app by name, and only install or update from there.

Similar attacks

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026