AI News Feed
Market watch
Cybersecurity

Kaspersky discovers Android malware turning car head units into proxy botnet

Kaspersky researchers found Android malware targeting DoFun car head units via TWCore updates, aiming to build a botnet of connected cars. The campaign is attributed to MoYu Group, and DoFun has patched the vulnerabilities.

According to Kaspersky, the attack exploits an analytics and software update application called TWCore, which runs on DoFun's Android-based head units. The attackers abused TWCore's update mechanism, instructing it to download a malicious APK. The malware is then placed in the app's cache directory and installed by the legitimate com.tw.core package.

Kaspersky described the attack as multi-stage. In the first stage, a small dropper with no user interface is deployed. It decrypts embedded data and extracts information needed for the next stage. In the second stage, the loader contacts the attackers' server and receives instructions for stage three, which can range from deploying additional malware to running a reverse proxy named “zhima.”

Although the malware has multiple functions, Kaspersky believes the real goal is to assimilate the vehicles into a botnet. Some cars come with a SIM slot and are online 24/7, making them potentially ideal devices for a malicious botnet, the researchers noted.

Kaspersky attributed the campaign to MoYu Group, a threat actor previously observed building the BadBox botnet from Android smartphones, tablets, streaming devices, and other internet-connected hardware. The researchers said they notified DoFun about the distribution scheme, and the vendor subsequently reported fixing the security issues.