Act
active
Corp MDM Android Spyware Targets Logistics Firms via Fake Play Pages
- Engineer — Learn: No cloud/infra vulnerability here — this is a social-engineering/sideload campaign against mobile devices. Worth reviewing Android fleet policy and app allowlisting if logistics operations are in scope, but no patch or config action is required today.
- SOC/IR — Act: Sweep MDM inventory for devices with the package ‘com.corp.mdm’ installed, and hunt for recent APK sideloads from unofficial sources on devices assigned to logistics or supply-chain roles.
- Leader — Learn: An active mobile campaign impersonating real logistics brands (CEVA, TKW) is relevant context for the risk register if the organization operates in or depends on logistics; no immediate leadership action required unless direct exposure is confirmed.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.