A real campaign is targeting logistics firms with fake Google Play pages impersonating well-known logistics brands to trick employees into installing an Android spyware app. Once installed, the spyware can steal newly received SMS messages (including one-time passcodes) and enable call forwarding, which can help criminals take over accounts. The same infrastructure is also used for credential-phishing lures and delivering Windows malware aimed at logistics organizations.
How the attack worked
This campaign targets logistics organizations by impersonating trusted brands. Attackers built fake Google Play pages branded as CEVA and TKW Logistics, then directed employees to sideload an Android APK disguised as a system service rather than installing it through the official app store. Once installed, the app requests SMS, telephony, and notification permissions under the guise of normal app functionality.
The malware is designed to exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service. This combination lets attackers intercept one-time passcodes sent over SMS and reroute calls, both of which support account takeover. Notably, the spyware only captures messages received after permissions are granted, not the entire inbox, which can make its activity less obvious to a casual check of message history.
The same infrastructure supporting this spyware also hosts credential-phishing lures and delivers additional Windows malware aimed at the logistics sector, indicating a broader, multi-channel operation rather than an isolated mobile threat.
Why it succeeded
The attack leans on trust in familiar brand names and the Google Play name itself. Field staff, drivers, and dispatchers who are used to installing work-related apps on Android devices may not scrutinize a link claiming to come from a known logistics provider. Because the page is branded to look like an official app listing, the sideloading step, normally a red flag, can be overlooked in a fast-paced operational environment.
A related part of this ecosystem uses phishing pages that impersonate legitimate logistics platforms employees already use daily. By intercepting logins and multi-factor authentication codes in real time, attackers can bypass the added protection MFA is meant to provide.
What to watch for
- Links directing you to install an app from a website rather than the official app store
- Any Android app requesting SMS, telephony, or notification permissions that doesn't match its stated purpose
- Unexpected sign-in prompts for logistics platforms, especially those framed as urgent shipment or invoice updates
- Requests to share a multi-factor authentication code outside your normal login flow
Building resistance
Organizations in transportation and warehousing should reinforce that mobile apps are only installed through official app stores or an approved internal process, never through a link in a message or email claiming to be a Play Store page. Teams should also be reminded that legitimate platforms will never ask them to read back or forward an MFA code, and that unexpected shipment or invoice changes should be verified through known, trusted contact channels rather than the link or message that raised the request. Building this habit across dispatch, operations, and field staff reduces the chance that a convincing brand impersonation leads to a real compromise (see attack.mitre.org for technique T1204.001).
Key findings
- Attackers used "fake Google Play pages branded as CEVA and TKW Logistics" to distribute an Android APK posing as a system service (package: "com.corp.mdm").
- The spyware is designed to "exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service," enabling interception of one-time passcodes and call forwarding.
- The same infrastructure ("69.55.61[.]82") was used for command-and-control and also "hosting credential-phishing lures and serving additional Windows malware targeting the logistics sector."
- Corp MDM only steals SMS received after permissions are granted: "limited to new inbound messages after the permission is granted" (not the full inbox).
- A broader, logistics-focused criminal ecosystem is described, including phishing-as-a-service that used impersonation of legitimate logistics platforms and included "spear-phishing and voice phishing techniques" targeting logistics Telegram groups.
Who’s being targeted
- Commonly targeted roles: Operations/Dispatch, Drivers/Field staff, Finance/AP, IT/Helpdesk, Logistics coordinators.
- Affected industries: Logistics, Freight / Trucking, Transportation and Warehousing.
- Attack channels: website.
- Impersonated: Google Play / logistics brand (CEVA or TKW Logistics), Legitimate logistics platforms used daily by targets.
Red flags to watch for
- App is installed from a website (sideloaded), not the real Play Store
- Brand domain looks unusual (e.g., not an official company domain)
- App requests SMS/telephony permissions that don't match a normal logistics app update
- Unexpected login request or urgent 'shipment/invoice' prompt
- Login page hosted on unfamiliar domain/IP infrastructure
- Any request to share MFA codes outside normal authenticator flow
Frequently asked questions
How do attackers deliver the spyware to logistics employees?
They use fake Google Play pages branded as real logistics companies like CEVA and TKW Logistics to distribute an Android APK file disguised as a system service, which is sideloaded rather than installed from the official app store.
What can the spyware do once installed?
It requests SMS, telephony, and notification permissions, allowing it to exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service, which can be used to intercept one-time passcodes.
Does the spyware read a victim's entire text message history?
No, the malware is limited to new inbound messages after the permission is granted, not the full inbox.
Is this campaign only about mobile spyware?
No, the same infrastructure also hosts credential-phishing lures and delivers additional Windows malware targeting the logistics sector.
Read the video transcript
Imagine you’re on your work phone and see a “Google Play” page for CEVA or TKW Logistics telling you: install this required Android service update. You tap install, it sideloads an app called com.corp.mdm, and suddenly it wants SMS, phone, and notification access. That’s spyware built to grab new text messages, including one-time passcodes, and even divert calls, using the same 69.55.61.82 setup that also runs fake login pages for our logistics platforms. Here’s the twist: it only needs new texts after you tap Allow. That’s enough to catch the next MFA code you expect, while a fake shipment or invoice login page on that same 69.55.61.82 site tricks you into entering your password and then reading out or approving that code. If you ever get a link to a “Google Play” page for a logistics app, stop, open the real Play Store yourself, search the app by name, and only install or update from there.