New Android Malware Spotted Infecting Cars Via Software Updates

In an unexpected turn of events, a new strain of Android malware has emerged, specifically targeting the computing systems embedded within vehicles. This malware is engineered to infiltrate “automotive head units,” which are responsible for managing infotainment systems, connectivity, and navigation functionalities. The discovery was made by the antivirus firm Kaspersky in June, marking a significant moment in cybersecurity.

Details of the Discovery

Kaspersky’s findings indicate that this is the first documented instance of malware affecting a car head unit, with a unique infection chain tailored for this type of device. The malware was identified within the built-in firmware updaters of the Android-based head unit software developed by DoFun, a company headquartered in Hong Kong. DoFun specializes in providing software themes and hardware accessories for automotive head units.

The malware operates under the guise of an enigmatic application known as JarService. Kaspersky noted that the installation process resembled that of a typical user application, yet it lacked any user interface, raising suspicions that it might be infiltrating users’ devices without their awareness.

Mechanism of Infection

The delivery of this malware was facilitated through a function named TWCore, which is a legitimate system application designed for collecting analytics data and updating head unit software. Kaspersky’s investigation suggests that there was an intrusion into DoFun’s IT systems, allowing the malware to be distributed through a legitimate update mechanism.

Implications of the Malware

This discovery is particularly striking given that Android malware typically targets smartphones, which house more sensitive information such as passwords and access to banking applications. In this case, however, Kaspersky uncovered evidence indicating that the malware aimed to convert the car’s head unit into a “botnet,” effectively creating a network of infected devices. The malware is equipped with nine commands, including the ability to download and execute code and open web links. Kaspersky suspects that the ultimate objective was to exploit the infected head units for displaying advertisements and simulating interactions to perpetrate online ad fraud.

Response and Related Threats

In response to these findings, Kaspersky promptly notified DoFun, which subsequently reported that it had addressed the security vulnerabilities. Furthermore, Kaspersky has drawn parallels between this car-based malware and another Android threat known as BadBox, noting similarities in naming patterns and significant overlaps in infrastructure. Last year, researchers uncovered the BadBox 2.0 malware circulating on millions of unbranded Android-based streaming devices, tablets, and digital projectors, likely due to preinstalled malicious code. Google took legal action to mitigate this threat, alleging that the creators of BadBox were based in China.

AppWizard
New Android Malware Spotted Infecting Cars Via Software Updates