started · updated
Android malware targets vehicle infotainment systems via official updates
Kaspersky researchers have identified a novel Android malware campaign specifically targeting automotive head units, which are the Android-based infotainment and control systems in many modern vehicles. This marks the first documented case of an infection chain tailored for this specific type of device.
The malware is distributed through the official firmware update mechanism of several Android-based head unit models powered by DoFun. The attack exploits a legitimate system application called TWCore, which is responsible for analytics and software updates. By leveraging this trusted channel, attackers use a dropper known as JarService to install malicious software.
The campaign is believed to be linked to the MoYu Group and the BadBox botnet. Once installed, the malware operates stealthily in the background without a user interface. Its primary objectives include conducting large-scale ad fraud and turning the compromised vehicles into nodes for a proxy botnet to redirect internet traffic. The malware can also collect device data and download additional malicious components.
DoFun has reportedly addressed and fixed the security vulnerability within the TWCore update function.
Entities
Android · BADBOX · DoFun · Kaspersky · MoYu Group
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 6 SOURCES] The malware is a multi-stage downloader designed for ad fraud and the creation of a proxy botnet. cybernoz.com · it-online.co.za · vosveteit.zoznam.sk · www.ad-hoc-news.de · www.internethaber.com · +1 more
- [● 6 SOURCES] Kaspersky researchers identified the first documented malware infection specifically targeting Android-based car head units. cybernoz.com · it-online.co.za · vosveteit.zoznam.sk · www.ad-hoc-news.de · www.internethaber.com · +1 more
- [○ 1 SOURCE] The malware can display unwanted ads, perform click fraud, collect device data, and download additional malicious software. www.ad-hoc-news.de
- [● 6 SOURCES] The malware is distributed via the official firmware update mechanism of Android-based head units. cybernoz.com · it-online.co.za · vosveteit.zoznam.sk · www.ad-hoc-news.de · www.internethaber.com · +1 more
- [● 2 SOURCES] The vendor DoFun has reportedly fixed the security issue. it-online.co.za · www.ad-hoc-news.de
- [● 5 SOURCES] The infection chain exploits a legitimate system application called TWCore, which is used for analytics and updates. it-online.co.za · vosveteit.zoznam.sk · www.ad-hoc-news.de · www.internethaber.com · mobilsiden.dk
- [● 4 SOURCES] Attackers use a dropper named JarService to deliver the malware to the head units. it-online.co.za · www.ad-hoc-news.de · www.internethaber.com · mobilsiden.dk
- [● 4 SOURCES] The campaign is believed to be attributed to the MoYu Group, which is linked to the BadBox botnet. it-online.co.za · www.ad-hoc-news.de · www.internethaber.com · mobilsiden.dk