Researchers at Kaspersky have come across what appears to be the first malware specifically designed for car head units, and have found links to the notorious BadBox botnet.
The malware was discovered on an Android-powered aftermarket infotainment system made by Chinese company DoFun, which is widely used in China and other APAC countries.
Threat actors exploited a vulnerability in a system designed to handle software updates, enabling them to deliver malware to vehicle head units, Kaspersky explained. The vendor said it addressed the weakness after being notified.
The attackers compromised the update distribution channel to deliver stealthy malicious Android applications that served as droppers, loaders, clickers, and reverse-proxy loaders.
The malware supports nine commands, including ones that enable its operators to display ads, conduct ad fraud (via the clicker component), and download additional components.
However, Kaspersky researchers have observed only commands to download a reverse proxy module, suggesting that the main goal is to ensnare devices in a proxy botnet.