First malware specifically designed for Car Head Units Fuels Botnet

First malware specifically designed for Car Head Units Fuels Botnet

Kaspersky researchers have encountered what appears to be the first malware designed specifically for car head units and found links to the infamous BadBox botnet.

The malware was discovered on an Android-based aftermarket infotainment system from Chinese company DoFun, which is widely used in China and other APAC countries.

Threat actors exploited a vulnerability in a system designed to process software updates, allowing them to deliver malware to the main units of vehicles, Kaspersky explained. The provider said it fixed the vulnerability after being notified.

The attackers manipulated the update distribution channel to secretly deliver malicious Android applications that acted as droppers, loaders, clickers, and reverse proxy loaders.

The malware supports nine commands, including those that allow its operators to display ads, perform ad fraud (via the clicker component), and download additional components.

However, Kaspersky researchers have only observed commands to download a reverse proxy module, suggesting that the main goal is to include devices in a proxy botnet.

Advertising. Scroll to continue reading.

Further analysis led the security company to strongly believe that the malware was the work of MoYu Group, one of several entities previously linked to the development and operation of the BadBox botnet.

BadBox has been around since at least 2023 and allows its operators to use hacked Android devices for fraud and other illegal activities.

Law enforcement has tried to disrupt it, but the threat has grown exponentially. Google filed a lawsuit against the operators of BadBox 2.0 last year, warning that the botnet had infected more than 10 million Android devices, mostly TV boxes.

BadBox malware is often pre-installed on low-cost devices, but attacks on vehicle infotainment systems show that operators are expanding their delivery methods and targets.

Related: Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the spotlight

Related: Rust supply chain attack linked to North Korean hackers

Related: AmnesiaStealer macOS malware steals data and controls browser sessions

Leave a Reply

Your email address will not be published. Required fields are marked *