A sophisticated supply-chain attack is infecting Android-based car infotainment systems. Hackers are turning vehicles into proxy botnet nodes for advertising fraud.
- Hackers are targeting Android-based automotive head units via supply-chain attacks.
- The malware utilizes legitimate device-update apps to spread undetected.
- Infected devices are used for residential proxy botnets and ad fraud.
- No immediate threat to critical vehicle driving or control systems was detected.
In a significant escalation of automotive cyber threats, hackers have begun infecting Android-based car head units with sophisticated proxy botnet malware. This supply-chain attack exploits legitimate device-update applications to deploy malware that enlists compromised vehicles into a massive proxy network or utilizes them for large-scale advertising fraud.
Security researchers at Kaspersky have analyzed the malware and attributed the campaign to the MoYu group, a known threat actor previously linked to the infamous BadBox malware botnet. Notably, this marks the first documented instance of a malware infection chain specifically engineered to target car head units.
The Mechanics of the Attack
The operation specifically targets systems provided by DoFun, a Chinese automotive software and hardware provider owned by Shenzhen Driving Control Technology Co., Ltd. DoFun supplies generic Android-based head units that serve as the central command hub for a vehicle's infotainment, navigation, and settings.
In June, researchers identified a rogue APK being downloaded from TWCore, a legitimate DoFun system app. This malware, identified as JarService, operates without a user interface. Once launched, it executes a second-stage loader that establishes a connection with a command-and-control (C2) server, allowing attackers to retrieve device metadata such as MAC addresses, Wi-Fi SSIDs, and display resolutions.
Why This Matters
BozokMedia analysis shows that the increasing connectivity of modern vehicles creates a massive, overlooked attack surface. As cars become increasingly reliant on software-driven interfaces, they provide hackers with high-quality 'residential' IP addresses, making their malicious traffic appear legitimate and much harder for traditional security systems to block.
This attack highlights the vulnerability of the automotive supply chain, where a single compromised update can jeopardize millions of connected devices.
The malware supports a variety of commands, including executing JavaScript, downloading additional modules, and performing traceroutes. While the technical capabilities are extensive, Kaspersky emphasizes that the malware is designed for monetization through advertising fraud and does not interfere with critical vehicle control systems like braking or steering.
Frequently Asked Questions
1. Can this malware cause a car accident?
No, the current analysis suggests the malware targets the infotainment system and does not access critical driving controls.
2. How can drivers protect themselves?
Ensure that all automotive software updates are sourced only from official manufacturer channels and remain vigilant about unusual system behavior.