Malware infects Android-based automotive head unit firmware(securelist.com)
262 points by campuscodi 18 days ago | 140 comments
tl;dr: Kaspersky discovered Android malware distributed via the legitimate update mechanism of DoFun automotive head unit firmware — the first documented case of malware with an infection chain specific to car head units. The multi-stage downloader ultimately deploys a reverse proxy module ("zhima") to enlist infected devices into a residential proxy botnet, and also supports ad fraud commands. Researchers attribute the campaign with high confidence to MoYu Group, an actor linked to the BADBOX botnet, based on code naming conventions and infrastructure overlap with residential proxy services like PXYEDGE and ProxyForU.
HN Discussion:
  • ~Clarifies the malware is limited to cheap Chinese head units via official OTA, not a broader Android threat
  • Worries about escalation risks like lateral spread to phones or exploitation of CAN bus access to cause crashes
  • Views this as an inevitable consequence of the automotive industry's poor security practices
  • Speculates about downstream uses of the botnet, such as selling proxies for AI scraping or click fraud
  • Questions the attack chain mechanics, e.g. whether attackers had to compromise update servers