HomeMalware & ThreatsCar Infotainment Malware Creates Criminal Proxy Botnet

Car Infotainment Malware Creates Criminal Proxy Botnet

Published on

spot_img

Malware Targets DoFun Automotive Software Updates, Compromising Android Head Units

Car Infotainment Malware Creates Criminal Proxy Botnet
Image: Shutterstock

Recent investigations have revealed that malware operators have exploited vulnerabilities in Android-based car infotainment systems, specifically through compromised software updates, effectively converting vehicles connected to the internet into nodes for a criminal proxy botnet. This alarming trend raises serious concerns regarding the cybersecurity of automotive technologies.

According to findings from Kaspersky, a prominent Russian cybersecurity firm, a multi-stage strain of Android malware has been identified, primarily affecting automotive software and hardware manufactured by the Chinese company DoFun. What captured the attention of the cybersecurity experts at Kaspersky was the unique behavior exhibited by the malware.

Kaspersky observed that the malware installs similarly to any standard user application but does not attempt to disguise itself as legitimate software. Notably, it operates without any user interface, which sets it apart from more conventional malware that generally seeks to hide its true intentions.

Instead of cloaking itself within the existing software of a head unit or masquerading as a user-oriented application, the malware employs a more insidious approach. It capitalizes on legitimate update functionalities embedded within Android firmware, allowing it to infiltrate systems without triggering user suspicion.

Researchers traced the path of infection back to an application known as TWCore, which is typically pre-installed on DoFun head units. By exploiting the application’s download functionality, threat actors managed to install a malicious dropper known as JarService onto the units, all without the users’ knowledge.

Once JarService is installed, it activates silently, since it lacks any visible interface. This dropper subsequently loads a second-stage payload, which then signals the attacker-controlled infrastructure to retrieve additional malicious code. The third-stage payload, referred to as “zhima” by researchers, is designed to engage in ad fraud and to convert compromised head units into reverse proxies.

The reverse proxy functionality allows cybercriminals to redirect internet traffic, creating the illusion that the data originates from the vehicle’s internet connection. Kaspersky points out that, while a car’s head unit typically does not hold high-value assets for attackers, employing ‘classic’ Android malware is a strategic move to recruit devices into a botnet, akin to previous attacks targeting Internet of Things (IoT) devices.

This incident marks a significant milestone, being the first recorded case of malware deliberately targeting an automotive head unit. Kaspersky has attributed the malicious activities to the MoYu Group, a threat actor closely linked to notorious campaigns such as Badbox and Badbox 2.0, which have previously targeted Android smartphones, streaming devices, tablets, and smart television applications. Collectively, these campaigns have reportedly infected over 1 million devices globally.

Initially uncovered by Human Security in 2023, the Badbox campaign went on to affect an additional 30,000 IoT devices but faced disruption in December 2024 thanks to the proactive interventions of Germany’s Federal Office for Information Security.

In response to the cyberthreat, Kaspersky took the initiative to inform DoFun about the malware scheme, prompting the company to implement a security fix through an infrastructure update. This highlights the critical importance of ongoing cybersecurity efforts in protecting modern vehicles, which increasingly rely on complex software functionalities as part of their infotainment systems.

The evolving nature of cyber threats, particularly in sectors as sensitive as automotive technology, underscores the necessity for manufacturers to remain vigilant and proactive in addressing vulnerabilities. As vehicles become ever more connected, the risks associated with cyberattacks will continue to grow, necessitating robust security measures and real-time updates to safeguard against potential exploitation.

Source link

Latest articles

Multi-Agent AI Framework Breaches Government Systems and Acquires Thousands of Records

Multi-Agent AI Framework Compromises Government Systems in Asia A groundbreaking incident involving a sophisticated multi-agent...

Fake Recruiter Scams Exploit Corporate Credentials via Mobile Devices

Fake Recruiter Scams Targeting Corporate Credentials on Mobile Devices: A Growing Concern In an alarming...

Iran-Linked Hackers Accused of Cyberattack on UK Energy Sector

A recent cyberattack, reportedly linked to Iranian hackers, has raised significant concerns regarding the...

AI Assists Chinese-speaking Hackers in Accelerating Attacks on Vulnerable Servers

Cybercrime Group Leverages AI to Launch Attacks on Web Servers In a critical revelation from...

More like this

Multi-Agent AI Framework Breaches Government Systems and Acquires Thousands of Records

Multi-Agent AI Framework Compromises Government Systems in Asia A groundbreaking incident involving a sophisticated multi-agent...

Fake Recruiter Scams Exploit Corporate Credentials via Mobile Devices

Fake Recruiter Scams Targeting Corporate Credentials on Mobile Devices: A Growing Concern In an alarming...

Iran-Linked Hackers Accused of Cyberattack on UK Energy Sector

A recent cyberattack, reportedly linked to Iranian hackers, has raised significant concerns regarding the...