CuraSec

Act active

Corp MDM Android Spyware Targets Logistics Firms via Fake Play Pages

2026-09-24 15:49 UTC · The Hacker News · read the source ↗ #android-spyware#logistics-sector#mobile-threat
  • Engineer — Learn: No cloud/infra vulnerability here — this is a social-engineering/sideload campaign against mobile devices. Worth reviewing Android fleet policy and app allowlisting if logistics operations are in scope, but no patch or config action is required today.
  • SOC/IR — Act: Sweep MDM inventory for devices with the package ‘com.corp.mdm’ installed, and hunt for recent APK sideloads from unofficial sources on devices assigned to logistics or supply-chain roles.
  • Leader — Learn: An active mobile campaign impersonating real logistics brands (CEVA, TKW) is relevant context for the risk register if the organization operates in or depends on logistics; no immediate leadership action required unless direct exposure is confirmed.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.