Corp MDM Spyware: Settings That Stop Fake Play Installs
How the Corp MDM Android spyware used fake Google Play pages to steal SMS and forward calls, and the four phone settings that stop it on company devices.
The Corp MDM spyware is an Android app that pretends to be a company device management tool. It is installed from fake Google Play pages, then reads new text messages and can forward the phone’s calls to a number the attackers choose. The fix for a company phone is mostly one setting: block apps from outside Google Play.
Here is how the campaign worked, why logistics staff were the target, and what to switch on so a link like this goes nowhere on your phones.
How the Corp MDM spyware works
According to The Hacker News report on the Corp MDM spyware, the attackers built fake Google Play pages that impersonated two logistics platforms, CEVA and TKW Logistics. The pages offered an APK, an Android app file, to download and install by hand. That is sideloading, and it skips the real Play Store entirely.
Once installed, the app asked for SMS, telephony and notification permissions. With those it could:
- Read new text messages as they arrived, with the sender, message body and timestamp, and send them to the attackers. It did not grab older messages already in the inbox.
- Turn on call forwarding. The operators could send a command that set unconditional call forwarding to a number they picked, and cancel it later with the ##21# code.
- Show its own notifications on the phone.
The campaign was found and analysed by researcher Ben Folland of Have I Been Squatted. The report also notes the malware has bugs that get in the way of its own features. Don’t take much comfort from that. Buggy spyware that reads your texts is still reading your texts.
Why SMS and call forwarding matter to a small business
If sign-in codes for email, banking or a supplier portal are texted to that phone, an attacker reading new SMS sees them the moment they arrive.
Call forwarding is quieter. Picture a delivery driver whose phone number is on every dispatch sheet. Forward that number, and customer calls, depot calls and “please confirm this payment change” calls all go to someone else. The driver just thinks it has been a slow day.
Logistics firms were the target this time, but the method would work on a plumbing company’s technicians or a clinic’s on-call phone just as well. Anyone who gets texts from a platform they trust can be sent a fake “update your app” link.
Why the name “Corp MDM” is a warning in itself
The app used the idea of company device management as cover. Staff who have been told “the company manages your phone” are more likely to install something that claims to be the company’s tool.
It helps to know how real company device management arrives on an Android phone. With Android Enterprise, a company-owned phone is enrolled by factory resetting it and scanning a QR code during setup. NounDesk works this way and has no agent app to download at all. So you can give staff a simple rule: the company will never send you a link to install a management app. If a message asks you to, it is not from us.
Four settings that stop fake Play installs on company phones
Each of these is a setting in a NounDesk security policy. Any decent Android MDM should offer the same.
1. Block apps from outside Google Play
This is the one that stops Corp MDM. With apps outside Google Play blocked, a downloaded APK won’t install, no matter how convincing the page was. Your staff can tap the link, download the file and still get nowhere.
Most small businesses never need sideloading. If you publish your own app, you can put it in managed Google Play privately, visible only to your devices. For the wider app picture, read how to stop employees installing apps on work phones.
2. Keep Play Protect on
Play Protect is Android’s built-in scanner for harmful apps. Require it in policy so nobody can switch it off to get an app installed.
3. Mark the apps people need as Required
When a driver’s dispatch app is marked Required in the policy, it arrives on the phone from Google Play and updates from there. Nobody has a reason to go hunting for an “update” on a web page. Other apps can be Available, so staff pick from a list you approve, or Blocked.
4. Require screen lock and encryption
These don’t stop the spyware. They do limit the damage when a phone is lost with a signed-in session on it. If a phone does go missing, here is what to do in the first hour.
How to check your fleet after an alert like this
Open your mobile device management dashboard and check three things.
First, confirm every policy has apps outside Google Play blocked and Play Protect on. In NounDesk, the publish preview shows how many devices a change affects before you save it, so tightening a loose policy is a two-minute job.
Second, look at the app compliance view for anything unexpected. A company phone should only have apps you chose.
Third, check patch age. Spyware that asks for permissions is one problem. Old security patches are another way in. See how to keep company Android phones updated for checking patch levels and setting up a monthly routine.
What to do this week
- Block apps outside Google Play in every policy on your company-owned devices.
- Confirm Play Protect is required in the same policies.
- Send staff one sentence: “We will never send you a link to install a company app. If you get one, forward it to me and don’t install it.”
- Review the app list on a few phones, or the app compliance view if you have one.
- Ask one person to check call forwarding in the phone app settings if they have seen anything odd, such as calls they expected and never got.
FAQ
What is Corp MDM spyware?
Corp MDM is Android spyware spread through fake Google Play pages that impersonated logistics platforms. It steals newly received text messages and can set up call forwarding to a number the attackers choose.
How do I stop employees sideloading apps on Android?
Block apps from outside Google Play in your Android MDM policy. With that setting on, a downloaded APK file will not install on the company phone.
Would a real MDM ever ask staff to install an app from a link?
Not with NounDesk. Company-owned phones are enrolled through Android Enterprise with a factory reset and QR code, and there is no separate agent app to download.
To lock down app installs across every company phone in one place, see how NounDesk manages Android fleets.