New Android Malware Targets In-Car Multimedia Systems
Security experts have identified a new Android malware targeting DoFun-powered in-car multimedia systems to conduct ad fraud.
Security experts have identified a new Android malware targeting systems that provide multimedia features and vehicle control functions. Designed as a multi-stage downloader, this campaign stands out as the first documented case targeting in-vehicle multimedia units.
Target of the Malware
Security experts have detected a new Android malware targeting in-car multimedia systems that combine multimedia and, in some cases, vehicle control functions.
Threat Actor Connection
The purpose of the attack was determined to be ad fraud and conducting other malicious activities. Researchers assess that this activity may be related to the MoYu Group, which is associated with the BadBox botnet.
Prevalence of the Systems
In-vehicle multimedia systems can be factory-installed or later integrated into older vehicle models. The choice of the Android operating system by manufacturers enables malware to run on these devices.
Abuse of the Update Mechanism
The software was distributed via integrated update mechanisms in the firmware of multimedia units powered by DoFun. The manufacturer was notified, and DoFun authorities reported that the issue has been resolved.
Infection Chain and Method
The infection process starts through a legitimate system application called TWCore. Attackers abused this channel to deliver malware to the vehicle units via an installer named JarService.
Stealthy Operation and Commands
The malware was installed on the system like a standard user application and, since it lacks any user interface, continued to run unnoticed in the background.
Information Collected
Analysts determined that the attackers defined nine different commands capable of displaying advertisements and downloading additional malicious modules. Furthermore, device and network information was also compromised.