Cybersecurity firm Kaspersky claims that it has uncovered a malware campaign targeting Android-based car head units.
In a press release today (Sept 29), the company states that the malware attack occurs in the form of a multi-stage downloader.
“The goal is to deploy multi-stage malware that could enable carrying out ad fraud and other malicious activities,” the company says.
This reportedly marks the first documented case of malware infecting a car’s head unit through an infection chain that was tailored for these vehicle systems, the firm adds.
Kaspersky explains that the malware was distributed via the update mechanisms built into the firmware of several Android-based head unit models powered by DoFun. According to DoFun, the issue has since been fixed.
The malware infection is said to originate from a legitimate system app called TWCore, which is responsible for collecting analytics and updating the vehicle head unit software. The app received instructions from the manufacturer’s server detailing which apps on the head unit needed to be updated or installed.
Bad actors reportedly took advantage of the update to deliver previously unknown malware directly to the head unit using a dropper – a type of Trojan horse program that secretly installs malicious software – called JarService.
The malware was then installed as a regular user application without a user interface and operated in the background without the user noticing.
Once installed, the attackers implemented nine distinct commands capable of displaying unwanted advertisements, executing ad fraud, and downloading additional malicious modules. Kaspersky also highlighted that the attackers received device information from head units such as display resolution, device model, connected WiFi network identifier, and more.
Researchers at Kaspersky believe that the malware campaign may be attributed to the MoYu Group, a threat actor closely tied to the BadBox botnet. While BadBox is known for factory pre-infected Android devices (smartphones, streaming TV boxes, and tablets), this campaign specifically targeted car head units through compromised software updates.
