Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

IoT Security

First Malware Built Specifically for Car Head Units Fuels Botnet

Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.

Car head unit malware

Researchers at Kaspersky have come across what appears to be the first malware specifically designed for car head units, and have found links to the notorious BadBox botnet.

The malware was discovered on an Android-powered aftermarket infotainment system made by Chinese company DoFun, which is widely used in China and other APAC countries.

Threat actors exploited a vulnerability in a system designed to handle software updates, enabling them to deliver malware to vehicle head units, Kaspersky explained. The vendor said it addressed the weakness after being notified. 

The attackers compromised the update distribution channel to deliver stealthy malicious Android applications that served as droppers, loaders, clickers, and reverse-proxy loaders.

The malware supports nine commands, including ones that enable its operators to display ads, conduct ad fraud (via the clicker component), and download additional components.

However, Kaspersky researchers have observed only commands to download a reverse proxy module, suggesting that the main goal is to ensnare devices in a proxy botnet.

Advertisement. Scroll to continue reading.

Further analysis led the security firm to strongly believe that the malware is the work of the MoYu Group, one of several entities previously linked to the development and operation of the BadBox botnet

BadBox has been around since at least 2023, enabling its operators to use hacked Android devices for fraud and other illegal schemes. 

Law enforcement has attempted to disrupt it, but the threat has grown exponentially. Google last year filed a lawsuit against the operators of BadBox 2.0, warning that the botnet had ensnared more than 10 million Android devices, mainly TV boxes. 

BadBox malware is often pre-installed on budget devices, but attacks targeting vehicle infotainment systems show that its operators are expanding their delivery methods and targets.

Related: Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Related: Rust Supply Chain Attack Linked to North Korean Hackers

Related: AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Frank Verdecanna has been appointed Chief Financial Officer at Armadin.

Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.

Skyhigh Security has named Anthony Palladino as Chief Operating Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.