| Malware infects Android-based automotive head unit firmware(securelist.com) | |
| 262 points by campuscodi 18 days ago | 140 comments | |
tl;dr: Kaspersky discovered Android malware distributed via the legitimate update mechanism of DoFun automotive head unit firmware — the first documented case of malware with an infection chain specific to car head units. The multi-stage downloader ultimately deploys a reverse proxy module ("zhima") to enlist infected devices into a residential proxy botnet, and also supports ad fraud commands. Researchers attribute the campaign with high confidence to MoYu Group, an actor linked to the BADBOX botnet, based on code naming conventions and infrastructure overlap with residential proxy services like PXYEDGE and ProxyForU. | |
HN Discussion:
| |