Hackers Are Using Fake Android Updates To Hijack Smart Car Displays

https://hothardware.com/contentimages/NewsItem/71459/content/16x9_2133x1200_highres-dofun-headunit.jpg

Cybersecurity researchers at Kaspersky have uncovered a malware downloader that targets Android-based automotive head units, marking the first documented case of malicious code explicitly engineered to compromise vehicle infotainment systems with the main intent of carrying out ad fraud.

The discovered campaign basically disguises as legitimate software update mechanisms to covertly deploy backdoors, turning hijacked dashboard displays into unauthorized proxy relays and platforms for malicious activities. According to Kaspersky's report on the matter, the infection chain targets aftermarket and factory-installed head units running software from firmware developer DoFun. Rather than relying on tricking drivers into downloading malicious applications manually, the attackers breached the update channel of a legitimate system component called TWCore.

Responsible for collecting device telemetry and pushing OTA system updates via an MQTT server hosted on cardoor[.]cn, TWCore was manipulated through a configuration setting known as installNotExists. This allowed the server to quietly force-install arbitrary application packages,...

Copyright of this story solely belongs to hothardware.com. To see the full text click HERE

Read more