AUTO-UPDATED

The invisible passenger in your car

Researchers have identified new Android malware targeting automotive head units, which exploits legitimate firmware update mechanisms to install a multi-stage downloader for ad fraud and proxy botnet operations.

Key Points

  • The malware, attributed to the MoYu Group, is the first documented instance of malicious software specifically infecting Android-based automotive head units.
  • Attackers leveraged the "TWCore" system application, which manages analytics and software updates, to silently download and install the malicious payload without user interaction.
  • The infection chain consists of three stages: a UI-less dropper, a loader that fetches additional code, and a final module that executes ad fraud and proxy tasks.
  • The final stage, known as the "zhima" module, turns the infected head unit into a node for a residential proxy botnet.
  • Security researchers confirmed the vendor of the affected DoFun head units has since patched the vulnerability used for the unauthorized app distribution.

Why it Matters

This discovery highlights a significant expansion in the attack surface for automotive systems, as attackers move beyond traditional mobile devices to exploit vehicle multimedia hardware. By compromising legitimate firmware update channels, malicious actors can turn factory-installed components into persistent botnet nodes, posing new security challenges for both vehicle manufacturers and consumers.
Securelist.com Published by Dmitry Kalinin
Read original