UPDATE

Botnets are spreading to new avenues, as researchers recently spotted Android malware for the first time targeting car head units, the hardware modules on dashboards that control vehicle communication, entertainment, and information systems.

Kaspersky researchers were monitoring Android threats in June when they found novel malware in an unusual place: the firmware of car head units. The researchers spotted what seemed like a typical head unit app, except for the fact that it lacked a user interface.

An analysis of the app revealed it was actually a multistage malware downloader, one designed to infect head units and spread by abusing a legitimate function.

“The malware spread through the built-in updaters of Android-based automotive head unit firmware,” Dmitry Kalinin, security researcher at Kaspersky, wrote in the threat report. “This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.”

Related:Dark Caracal Adds New Malware to Cyber Espionage Arsenal

Additionally, Kaspersky researchers traced the infection chain to a known cybercrime group, responsible for the notorious BadBox botnet, whose ultimate goal is to create a proxy botnet for click fraud purposes. The discovery shows that threat actors are leaving no device unturned when it comes to botnet campaigns.

Hacking Head Unit Firmware

Kaspersky researchers determined the Android malware, dubbed JarService, was targeting modules made by DoFun, a Chinese automotive technology manufacturer. Head units, Kalinin wrote, are Internet-connected devices — often with SIM card slots — that enable navigation systems.

“Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet — similar to attacks on IoT devices,” he wrote.

First, the good news: While Kalinin noted in his report that car head units have “partial control over certain vehicle functions,” a Kaspersky spokesperson tells Dark Reading that in this case, an infected DoFun head unit doesn’t present any physical risks to drivers or passengers, as the modules are purely infotainment systems.

The bad news, however, is that the Android loader can download additional malware, and it spreads by abusing an application, TWCore, in DoFun’s firmware that updates units’ software. Because TWCore had a weakness that enabled the installation of software not already present in the head units, threat actors behind this campaign abused the app to install the multistage loader.

Related:Pakistan’s Transparent Tribe Refreshes Toolset for Afghan Cyberattacks

According to Kaspersky’s report, the research team notified DoFun about the malicious activity, and the company reported that it had fixed the security issues. It’s unclear if other head units are being targeted; the Kaspersky spokesperson said the research team doesn’t know if head unit manufacturers have similar weaknesses with their built-in update systems.

Click-Fraud Botnets Spreading to Vehicle Systems

Kaspersky researchers tied the JarService infections to a familiar foe: the MoYu Group, which was also behind the notorious BadBox botnet. That botnet, which has rebounded from takedown efforts, also targeted Android devices.

Last year, research from Human Security’s Satori Threat Intelligence team noted that BadBad 2.0, a revamped version of the botnet, was infecting after-market infotainment vehicle systems, as well as smart TVs, digital projectors and other consumer IoT devices.

But unlike BadBox 2.0, MoYu’s new campaign appears to be specifically designed for a third-party vehicle module. Kalinin said the Android downloader eventually deploys both a Trojan clicker, or malware that’s designed to covertly click on Web ads, as well as a reverse-proxy module.

Lindsay Kaye, vice president of threat intelligence at Human Security, tells Dark Reading that the DoFun infections suggest a possible supply chain compromise. “While we can’t say with certainty which factor is driving this specific choice, we did identify this as a unique vector as part of BADBOX 2.0 that we had not seen involved in BADBOX,” Kaye says. “We believe these devices were infected via the supply chain and likely vendors (knowingly or unknowingly) flashing images to these Android-based devices that had the BADBOX backdoor.”

Related:‘Grandoreiro’ Malware Resurfaces With Mexico Campaign

Kaspersky’s research team observed several technical overlaps between the current campaign and MoYu’s infrastructure used in previous ad fraud activity, leading the cybersecurity vendor’s “high confidence” attribution. And while the spread of MoYu’s activity to vehicle systems is noteworthy, Kalinin also highlighted how the group has matured beyond previous distribution methods for this type of botnet malware, which include infected apps and pre-installed backdoors.

“The case examined here demonstrates an even more sophisticated delivery method: distribution through the legitimate update functionality of a system application,” he said.

Kalinin also wrote that as this is the first known malware targeting car head units, the devices will now require protections against such attacks. It’s unclear how infected DoFun modules can be remediated, if at all. Dark Reading contacted DoFun for comment but the company had not responded at press time.

This story was updated at 8:00 p.m. ET on August 26 to reflect comments from Human Security.





Source link

#

Comments are closed