Corp MDM Android spyware targeting logistics firms
Malware Activity
Summary
Hide ▲
Show ▼
The Corp MDM Android spyware operation is targeting the logistics sector with fake Google Play pages that deliver an APK designed to steal new SMS, divert calls, and keep covert device control. The malware uses the package name com.corp.mdm and communicates with infrastructure tied to 69.55.61.82. It also requests SMS, telephony, and notification permissions so operators can intercept messages and manage infected devices. The broader activity is paired with credential phishing and Windows malware, widening the risk to account access and shipment-related communications.
Related Happenings
RatHat Android credential-theft malware
Malware Activity
H score27
First: 17.09.2026 16:00
Last: 17.09.2026 16:00
Sources 1
About this happening:
RatHat is a new Android malware activity linked by Zimperium to China-based threat actors and focused on stealing banking credentials, 2FA/OTP data, notifi...
RatHat Android credential-theft malware
Malware ActivityAbout this happening: RatHat is a new Android malware activity linked by Zimperium to China-based threat actors and focused on stealing banking credentials, 2FA/OTP data, notifi...
Latest development: 18.09.2026 09:17
Zimperium said RatHat pairs Accessibility abuse with autonomous local ADB (Android Debug Bridge) self-pairing to break out of the Android sandbox, unlock Developer Options, enable Wireless Debugging, and extract the 6-digit ADB pairing code. The malware stages native daemons that execute with shell-level privileges, lets a Go Agent masquerading as liblocal-service.so apply persistence and power management exemptions, and can re-install itself through the local service after uninstall. The operator also uses an FRP reverse-proxy client to establish a persistent reverse tunnel to the C2 server, while the malware can record finger presses on screen with a hardware-level keylogger.
RatHat smishing-malvertising Android APK distribution campaign
Campaign
H score36
First: 17.09.2026 16:00
Last: 17.09.2026 16:00
Sources 1
About this happening:
RatHat is a newly disclosed Android malware campaign linked to China-based threat actors that spreads through malvertising, SMS phishing, and deceptive phishin...
RatHat smishing-malvertising Android APK distribution campaign
CampaignAbout this happening: RatHat is a newly disclosed Android malware campaign linked to China-based threat actors that spreads through malvertising, SMS phishing, and deceptive phishin...
Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware Activity
H score19
First: 10.09.2026 17:36
Last: 10.09.2026 17:36
Sources 1
About this happening:
The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...
Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware ActivityAbout this happening: The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...
Manic Android malware activity with offline relay exfiltration
Malware Activity
H score29
First: 20.08.2026 13:02
Last: 20.08.2026 13:02
Sources 1
About this happening:
Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
Manic Android malware activity with offline relay exfiltration
Malware ActivityAbout this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
RedWing Android spyware rented through Telegram
Malware Activity
H score21
First: 08.07.2026 18:30
Last: 08.07.2026 18:30
Sources 1
About this happening:
The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android spyware rented through Telegram
Malware ActivityAbout this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
Timeline
-
24.09.2026 15:05 2 articles · 2h ago
Corp MDM targets logistics firms through fake Google Play pages
Initial DisclosureCorp MDM is targeting the logistics sector through bogus Google Play pages branded as CEVA and TKW Logistics, delivering an Android APK named com.corp.mdm that disguises itself as a system service. The implant requests SMS, telephony, and notification permissions so it can intercept newly received SMS, divert calls, maintain a hidden foreground service, and keep background execution, while the associated infrastructure uses the hard-coded IP address 69.55.61[.]82 and hosts a password-protected admin panel on port 3456.
Show sources
- Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls — thehackernews.com — 24.09.2026 15:05
- Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls — thehackernews.com — 24.09.2026 15:05