In a rarity, a new piece of Android malware has been discovered specifically targeting the computing systems inside cars.
The malware was designed to infect “automotive head units,” which can control the infotainment system, connectivity and navigation, according to the antivirus provider Kaspersky, which uncovered the threat in June.
“This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device,” the company wrote in a Friday post.
The malware was discovered in the built-in firmware updaters for the Android-based head unit software provider DoFun, which is based in Hong Kong. DoFun appears to sell software themes, along with hardware accessories, for Android automotive head units. The malware was found operating as a mysterious app called JarService.”
“What struck us as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. This led us to suspect the app might be reaching users’ devices without their knowledge,” Kaspersky said when discovering the malware.
To deliver the malware, a function called TWCore was used, or what’s a “legitimate system application responsible for collecting analytics data and updating the head unit software,” Kaspersky said. The findings suggest someone tampered with DoFun’s IT systems to serve the malware over the legitimate update function.
It’s a surprising find since Android malware usually targets phones, which carry more valuable information, including passwords and access to banking apps. But in this case, Kaspersky discovered evidence that the malware was designed to enslave the car’s head unit into a “botnet,” or an army of infected computers. The malware possessed nine commands, including downloading and executing computer code and opening web links. As a result, Kaspersky suspects the ultimate goal was to use the infected head units to display ads and faking interactions with them to commit online ad fraud.
The antivirus provider said it notified DoFun, “and they subsequently reported fixing the security issues.” Kaspersky also suspects the car-based malware is related to another Android threat, called BadBox, citing “similar naming patterns and prominent infrastructure overlap between the activity.”
Last year, security researchers discovered the BadBox 2.0 malware circulating on millions of no-name Android-based streaming devices, tablet and digital projectors, likely because the malicious computer code was preinstalled on the devices. Google later filed a lawsuit to help shut down the threat, while alleging BadBox’s creators were based in China.
