Kaspersky has uncovered a new Android malware campaign specifically targeting vehicle infotainment screens. These systems, which sometimes blend multimedia entertainment with key car controls, have become the cybercriminals’ new target.
The cyberthreat uses a stealth downloader in multiple stages and represents the first documented case of this kind of malicious code infecting a vehicle’s infotainment display through an infection chain tailored exclusively to these automotive systems. The primary purpose of the cybercriminals is to deploy malware to carry out massive ad fraud and other harmful activities. According to researchers, this activity is believed linked to the MoYu Group, a threat actor closely related to the well-known BadBox botnet network.
Vehicle infotainment screens, whether factory-installed or aftermarket, routinely run the Android operating system to customize the interface and add key features. This allows most Android apps and malware to run on them. While these devices rarely store sensitive personal data, they have SIM card slots and continuous Internet connectivity for navigation maps and updates, making them an attractive entry point for cybercriminals.
Compromised updates as an entry point
The malware was distributed by exploiting the update mechanisms built into the firmware of several Android screen models from the DoFun supplier, which claims to have fixed the vulnerability after Kaspersky’s disclosure. The infection chain originated in the legitimate system TWCore app, responsible for collecting analytics and managing device updates. The attackers manipulated this channel to deliver directly a hidden installer program named JarService, which operated in the background with no user interface and without the driver noticing anything unusual.
Once inside, the criminals had nine distinct commands capable of displaying unwanted ads, carrying out ad fraud, and downloading additional malicious modules. The malware also collected technical information about the vehicle, such as screen resolution, model, connected Wi-Fi network, and the device’s physical address. Additionally, Kaspersky identified that the infrastructure of this cyberattack shares code and administration panels with illegal intermediary server services linked to BadBox, a massive network of infected Android devices used to misdirect unauthorized traffic and steal data.
«Despite the efforts of cybersecurity experts and authorities to dismantle networks like BadBox, cybercriminals continue to adapt their methods and infect devices worldwide. The distribution methods for this type of malware are increasingly varied: from preinstalled backdoors to compromised IPTV apps. In the analyzed case, we observed an even more sophisticated distribution method that exploits the legitimate software update functionality of a system app. Malicious actors are actively expanding to new platforms, and this harmful software is the first app designed specifically to infect vehicle displays through a tailored attack chain. This serves as a clear warning that modern automotive platforms urgently require robust protection against malware»,
stresses Dmitry Kalinin, a security researcher at Kaspersky.