Connect with us
Photo supplied.

GadgetWheels

The invisible malware passenger

Kaspersky has discovered a malicious campaign that targets a vehicle’s central dashboard system, writes GINA CASE.

Kaspersky, a global cybersecurity company, has uncovered a novel Android malware targeting vehicle head units – systems combining multimedia and, in some cases, car control functions.

The campaign takes the form of a stealthy multi-stage downloader. This is the first documented case of malware infecting a car’s head unit through an infection chain explicitly tailored for these vehicle systems.

The goal is to deploy multi-stage malware that would enable carrying out ad fraud and other malicious activities. Kaspersky researchers say the activity may be attributed to the MoYu Group, a threat actor closely tied to the infamous BadBox botnet.

Vehicle head units as the target

Car head units can be factory-installed or added to older vehicles after purchase. Manufacturers frequently use Android operating systems because they allow interfaces to be customised and essential system components to be added. As a result, most standard Android applications, as well as Android malware, can run on these devices.

Head units rarely store sensitive personal data, but many include SIM card slots and maintain constant Internet access for navigation and software updates. This connectivity can make them a potential target for attackers.

Compromised updates as the infection vector

The malware was distributed via the update mechanisms built into the firmware of multiple models of Android-based head units powered by DoFun. Kaspersky has notified the vendor regarding this software distribution abuse. According to DoFun, the issue has been fixed.

The infection chain originates from a legitimate system app called TWCore, which is originally responsible for collecting analytics and updating the head unit’s software. TWCore would get instructions from the manufacturer’s server detailing which apps on the head units needed to be installed or updated. Attackers leveraged this channel to deliver previously unknown malware directly to the head units using a dropper called JarService. The infection process was complex and multi-stage, designed to evade detection. The malware got installed as a regular user application but lacked a user interface, and it operated in the background without the user noticing. 

Kaspersky found that attackers had implemented nine distinct commands capable of displaying unwanted advertisements, executing ad fraud, and downloading additional malicious modules. Attackers received device information including display resolution, device model, connected Wi-Fi network identifier, and the MAC address of the device. 

Links to MoYu Group

Kaspersky uncovered links of this campaign to the MoYu Group, which is affiliated with the BadBox botnet, by comparing this campaign to previous attacks on TV set-top boxes. Furthermore, the administration panel of this botnet shares artifacts like embedded URLs in webpage code with residential proxy service websites PXYEDGE and ProxyForU. The BadBox botnet is a large-scale network of hijacked Android devices – streaming TV boxes, phones, and tablets – that come pre-infected with malware straight from the factory. Attackers use these hidden backdoors to commit ad fraud, steal data, and turn home networks into illegal proxy traffic relays.

“Despite the efforts of cybersecurity experts and law enforcement agencies to shut down the BadBox botnet, individual actors associated with it continue their malicious activities, infecting devices worldwide,” says Dmitry Kalinin, security researcher at Kaspersky. “The delivery methods for such malware are becoming highly varied – ranging from pre-installed backdoors to compromised IPTV applications.

“In this researched case, we observed an even more sophisticated delivery method exploiting the legitimate software update functionality of a system app. Malicious actors are actively conquering new platforms. This malware has become the very first malicious application specifically targeting car head units through an infection chain explicitly tailored for these vehicle systems. This serves as a warning that modern automotive platforms urgently require robust protection against malware.” 

* For more information, see the post on Securelist.com.

Subscribe to our free newsletter
To Top