New Android Malware Targets In-Car Multimedia Systems

Security experts have identified a new Android malware targeting DoFun-powered in-car multimedia systems to conduct ad fraud.

◉ 2 views
Araç içi multimedya sistemlerini hedef alıyor - Teknoloji Haberleri

Security experts have identified a new Android malware targeting systems that provide multimedia features and vehicle control functions. Designed as a multi-stage downloader, this campaign stands out as the first documented case targeting in-vehicle multimedia units.

Target of the Malware

Security experts have detected a new Android malware targeting in-car multimedia systems that combine multimedia and, in some cases, vehicle control functions.

Threat Actor Connection

The purpose of the attack was determined to be ad fraud and conducting other malicious activities. Researchers assess that this activity may be related to the MoYu Group, which is associated with the BadBox botnet.

Prevalence of the Systems

In-vehicle multimedia systems can be factory-installed or later integrated into older vehicle models. The choice of the Android operating system by manufacturers enables malware to run on these devices.

Abuse of the Update Mechanism

The software was distributed via integrated update mechanisms in the firmware of multimedia units powered by DoFun. The manufacturer was notified, and DoFun authorities reported that the issue has been resolved.

Infection Chain and Method

The infection process starts through a legitimate system application called TWCore. Attackers abused this channel to deliver malware to the vehicle units via an installer named JarService.

Stealthy Operation and Commands

The malware was installed on the system like a standard user application and, since it lacks any user interface, continued to run unnoticed in the background.

Information Collected

Analysts determined that the attackers defined nine different commands capable of displaying advertisements and downloading additional malicious modules. Furthermore, device and network information was also compromised.

Share