Car infotainment systems targeted by new malware campaign
Translated from Romanian and summarized by DistantNews. Read the original for the full story.
At a glance
- A malware campaign has targeted Android-based car infotainment systems, exploiting their software update mechanisms.
- The malicious software could display unwanted ads, commit advertising fraud, download additional components, and transmit device information.
- The system vendor was informed and has since fixed the vulnerability.
Car infotainment systems, often running on Android, have become a new target for cybercriminals. A recent malware campaign exploited the very mechanisms designed to update these systems, potentially compromising vehicle functions and user data.
Researchers at Kaspersky identified the campaign targeting DoFun multimedia systems. The malware was distributed through a legitimate system update application, TWCore. Attackers leveraged this trusted channel to install previously undetected malicious software that operated in the background without user awareness.
Once installed, the malware possessed a range of malicious capabilities. It could display intrusive advertisements, engage in ad fraud, download further malicious payloads, and exfiltrate sensitive device information. This included details like the device model, screen resolution, connected Wi-Fi network, and MAC address.
The vulnerability was reportedly exploited through a component called JarService. The attackers could send nine distinct commands to infected systems, highlighting the extensive control they could potentially gain. Researchers noted similarities between this campaign and the BadBox network, suggesting a potential link to broader cybercriminal operations.
Following the discovery, the vendor of the affected systems was notified. The company has since confirmed that the issue has been addressed and the vulnerability remediated, preventing further exploitation through this specific method.
Originally published by Adevฤrul in Romanian. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.