Android car systems abused by hackers to launch new malware that pulls devices into a hidden proxy network

https://cdn.mos.cms.futurecdn.net/huHCuSUqR6aadH7TQgGRs7-1920-80.jpg
  • Kaspersky found Android malware abusing DoFun car head units via TWCore updates
  • Multi‑stage attack installs loaders and reverse proxy, aiming to build a botnet of connected cars
  • Campaign attributed to MoYu Group; DoFun patched vulnerabilities after disclosure

We’ve seen botnets comprising cameras and DVRs, we’ve even seen botnets comprising smart fridges and digital frames, but we’ve never seen botnets comprising automobile infotainment systems. First time for everything.

Earlier this week, security researchers Kaspersky warned about finding a brand new Android malware targeting the car’s head unit. The victim seems to be a Chinese manufacturer called DoFun. Head units from this manufacturer, built on Android, are running an app for analytics and software updates called TWCore.

According to Kaspersky, the attackers abused TWCore’s update mechanisms, instructing it to download a malicious APK. This malware is then placed in the app’s cache directory and installed by the legitimate com.tw.core package.

No...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE