< Back to all clusters
[TECHNOLOGY] · 9 sources

started · updated

Android malware targets vehicle infotainment systems via official updates

Kaspersky researchers have identified a novel Android malware campaign specifically targeting automotive head units, which are the Android-based infotainment and control systems in many modern vehicles. This marks the first documented case of an infection chain tailored for this specific type of device.

The malware is distributed through the official firmware update mechanism of several Android-based head unit models powered by DoFun. The attack exploits a legitimate system application called TWCore, which is responsible for analytics and software updates. By leveraging this trusted channel, attackers use a dropper known as JarService to install malicious software.

The campaign is believed to be linked to the MoYu Group and the BadBox botnet. Once installed, the malware operates stealthily in the background without a user interface. Its primary objectives include conducting large-scale ad fraud and turning the compromised vehicles into nodes for a proxy botnet to redirect internet traffic. The malware can also collect device data and download additional malicious components.

DoFun has reportedly addressed and fixed the security vulnerability within the TWCore update function.

Entities

Android · BADBOX · DoFun · Kaspersky · MoYu Group

Claims

What the coverage asserts, and how many sources carry each claim.