Android car systems abused by hackers to launch new malware that pulls devices into a hidden proxy network
Kaspersky found Android malware abusing DoFun car head units via TWCore updates Multi‑stage attack installs loaders and reverse proxy, aiming to build a botnet of connected cars Campaign attributed to MoYu Group; DoFun patched vulnerabilities after disclosure We’ve seen botnets comprising cameras and DVRs, we’ve even seen botnets comprising smart fridges and digital frames, but we’ve never seen botnets comprising automobile infotainment systems .
First time for everything.
Earlier this week, security researchers Kaspersky warned about finding a brand new Android malware targeting the car’s head unit.
The victim seems to be a Chinese manufacturer called DoFun.
Head units from this manufacturer, built on Android, are running an app for analytics and software updates called TWCore.
According to Kaspersky, the attackers abused TWCore’s update mechanisms, instructing it to download a malicious APK.
This malware is then placed in the app’s cache directory and installed by the legitimate com.tw.core package.
No active campaigns The researchers said this was a multi-stage attack.
In the first stage, a tiny dropper with no user interface gets deployed.
It decrypts embedded data, and extracts the information it needs for stage two.
In the next stage, the loader contacts the attackers’ server and gets instructions about stage 3, which can be different things, from deploying additional malware, to running the “zhima” reverse proxy.
Despite its multifunctional nature, Kaspersky believes that the true goal of the campaign is to assimilate the cars into a botnet.
Some cars come with a SIM slot and are connected to the internet 24/7.
It is probably not an exaggeration to say that cars just might be the perfect devices for a malicious botnet.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.