Hackers have launched a campaign against car multimedia systems through the software update mechanism, Kaspersky Lab warned. Such systems are responsible not only for music and navigation but can also be linked to car functions. At the same time, internet access and SIM cards make them a potential target for attackers.
Hackers used the TWCore application, which is responsible for analytics and installing updates, to covertly download infected files using the JarService loader. Kaspersky Lab reported the problem to the manufacturer, DoFun, and according to the company, the vulnerability has already been fixed.
After installation, the malicious program operated covertly, without a visible interface. It could display unwanted advertisements, perform fraudulent actions, and download additional malicious modules. In addition, attackers collected device data — model, screen resolution, information about the connected Wi-Fi network, and MAC address.
Experts link the attack to the MoYu group, which was previously seen in campaigns against TV set-top boxes. Additional signs included elements found in the control panel of one of the malicious modules, including links to PXYEDGE and ProxyForU proxy services. The group is associated with the BadBox botnet — a network of infected Android devices, including TV set-top boxes, smartphones, and tablets. Attackers use such devices for advertising fraud, data theft, and transmitting internet traffic through other people's networks.
Dmitry Kalinin, a Kaspersky Lab expert, added that BadBox continues to pose a threat to Android devices worldwide. According to him, attackers are using more and more ways to spread malware — from pre-installed backdoors to infected IPTV applications. In the new campaign, they for the first time used a complex infection scheme specifically against automotive systems, taking advantage of a common software update application.