Threat Intelligence Brief
Curated summary with source attribution
Source: securityaffairs.com
Threat Risk: Medium
Victim: Users of DoFun Android-based car head units
Incident: Malware infection of Android car infotainment systems via the official firmware update mechanism.
Impact: Vehicle head units are recruited into a proxy botnet used for ad fraud.
Attacker: Unidentified threat actors
Analysis: Attackers exploited a legitimate system update app called TWCore to silently push malicious payloads to vehicle head units. The infection chain uses an MQTT message broker to bypass installation checks, deploying a multi-stage downloader. The final payload transforms these automotive devices into proxy bots used primarily for ad fraud.
Recommendations: Verify firmware update sources for automotive hardware; Monitor for unauthorized network traffic originating from vehicle infotainment systems; Pressure manufacturers to implement stronger signature verification for system updates
Source: SecurityAffairs / Kaspersky
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source