Android Car Head Units Targeted by Proxy Botnet Malware via Software Updaters

www.news4hackers.com-android-car-head-units-targeted-by-proxy-botnet-malware-via-software-updaters-android-car-head-units-targeted-by-proxy-botnet-malware-via-software-updaters

Android car head units compromised by proxy botnet malware via integrated software update mechanisms

Key Findings

According to findings by cybersecurity researchers, a previously unidentified Android malware is disseminated through the native update systems of affected Android-based car head units, transforming infected devices into ad-fraud mechanisms and components of a proxy botnet. This marks the first documented instance of malware discovered on a vehicle head unit with an infection pathway specifically tailored to this device category.

Attack Mechanism

Head units frequently incorporate SIM card slots and internet connectivity, enabling functionalities such as navigation and over-the-air updates. Given that these units typically lack sensitive data, a common attack vector involves leveraging them for botnet recruitment, mirroring tactics used against IoT devices. Researchers have linked the operation to the MoYu Group, a threat actor associated with the BADBOX botnet.

Compromised Devices

BADBOX is a global network of consumer electronics distributed through conventional supply chains, featuring pre-installed firmware backdoors. First detected in 2023 by HUMAN Security, the compromised devices utilize firmware from DoFun, a Chinese firm supplying infotainment systems for aftermarket car head units.

Infection Process

The initial compromise occurred through TWCore, a legitimate system application responsible for analytics collection and software updates. TWCore receives directives from a message broker hosted on the domain cardoor[.]cn, which instructs it on app file management. Notably, a specific message parameter includes an installNotExists flag, a Boolean value enabling TWCore to install applications absent from the original device configuration.

Phases of Infection

The infection process unfolds in three phases. The first stage involves a minimal dropper component named JarService, designed solely to unpack and pass control to the subsequent stage. The second stage functions as a loader, transmitting device metadata to a remote server before receiving further instructions. The third stage periodically communicates with a remote server every 90 minutes, transmitting details such as screen resolution, device model, connected Wi-Fi network name, and MAC address, while awaiting attacker commands.

Malware Capabilities

Researchers identified nine distinct command types embedded in the malware: return, copy, http, web, loadlib, loadlib2, loadlib3, deeplink, and traceroute. Only the http and loadlib2 commands were observed in active use, with loadlib2 facilitating the deployment of zhima, a reverse proxy module. Independent confirmation of this module’s presence was reported by Nokia’s Deepfield team on television set-top boxes during the same timeframe, reinforcing the attackers’ objective of constructing a proxy botnet.

According to researchers, “This case highlights an advanced distribution method leveraging legitimate system update mechanisms. The malware represents the first known malicious application targeting head units, necessitating enhanced security measures for these platforms.”

Response and Implications

Following responsible disclosure by Kaspersky, DoFun has addressed the vulnerability. The attack chain demonstrates evolving threat actor strategies, expanding into previously untargeted device categories. The integration of malware delivery through trusted update channels underscores the need for rigorous security protocols in automotive software ecosystems. The discovery emphasizes the growing importance of securing in-vehicle systems against emerging cyber threats.



About Author

en_USEnglish