Hackers Infect Car Infotainment Units, Android Is the Achilles’ Heel | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


The smarter cars are getting, the more exposed they are to cyberattacks that previously targeted PCs and phones.

This is the case with modern vehicles running Android, as security researchers at Kaspersky discovered new malware that can compromise an infotainment unit to provide attackers with control of the head unit and the ability to deploy additional payloads.

Before you get all worried that your Android-powered head unit might be at risk, you first need to check your manufacturer. Kaspersky says only Android head units running software developed by a Chinese company called DoFun are affected. The more concerning part is that the company claims its software is running in over 30 million vehicles worldwide – not just in China – so theoretically, all these vehicles are exposed to this new malware attack.

Compromising an Android-powered head unit running DoFun software starts by exploiting a service installed by the Chinese carmaker specifically to deliver software updates and install new apps.

Hackers found a way to use the service called TWCore specifically to install a malicious file called JarService.

Photo: DoFun

Once JarService lands on your head unit, the door is wide open for attackers to decide what they want to do next.

“The JarService code contains, in encrypted form, the next-stage payload, as well as information about its version and entry point. JarService’s job is to decrypt this data and launch the next stage of the infection: a malicious downloader,” Kaspersky explains.

This downloader connects to a command-and-control server, which attackers use to obtain additional information about the infected devices and the installed malware. This is pretty much the place attackers use to control an infected system.

For example, attackers can obtain data like the head unit model, the screen resolution, the wireless network it uses to access the Internet, and the MAC address. Hackers can send commands to the infected head unit, and they can even open web pages remotely.

DoFun Android head units

Photo: DoFun

“But most importantly, it can download and execute additional malicious code on the compromised car’s infotainment system,” security researchers explain.

For example, attackers can make your head unit part of a botnet and use it as a proxy server to route traffic through the device. They can also carry out further attacks using your infotainment system.

All these additional tasks are powered by another payload called zhima. Kaspersky discovered that the hacking group behind these attacks could be MoYu Group.

“While investigating the botnet infrastructure, our experts discovered links between MoYu Group and the PXYEDGE and ProxyForU services, which offer residential proxy services,” the security firm notes.

Obviously, compromising your infotainment unit and making it part of a botnet can have a major impact on the performance of the head unit, especially as its resources are being used to carry out all these malicious activities.

The first thing you’ll observe is that everything is significantly slower on your infotainment screen. For example, when you launch apps like Google Maps, Waze, Spotify, or YouTube Music, it’ll take longer for these apps to load. This is because your head unit uses its resources to run the activities executed by the attackers in the background.

Second, the Internet speed could also decrease substantially. You can observe a slower Internet connection when using web apps, such as YouTube Music and Spotify. If these apps need more time to load a song or download it, there’s a chance that your infotainment system is part of the botnet and it acts as a proxy server for someone online.

However, the most concerning part is that once they deploy the necessary malware on an infected head unit, attackers can do pretty much anything they want, as they obtain full control over the device.

“The malware’s capabilities are not limited to providing proxy functionality. It can receive commands from the attackers, and download and execute additional malicious code. As a result, the consequences of an infection may vary depending on what payload the botnet operators decide to install on the device,” Kaspersky explains.

DoFun Android head units

Photo: DoFun

There are several notable tidbits that Android-powered head unit owners must have in mind. First, only those infotainment systems produced by the Chinese company are affected.

Second, the attacks work only if your device is connected to the Internet, such as when using a data plan or your phone’s hotspot to access the web. If you only use such a head unit offline for things like navigation with offline maps, there’s no way for attackers to compromise your system.

A patch has already been deployed to block the way attackers exploit the update service in the head unit, so if you own an infotainment system from the Chinese company, you’d better install the most recent software version. Go online, check for updates, and install the newest update to make sure the exploit is blocked.

If no software update is available, you should contact the parent company to ask for assistance on how to install the patched firmware update in your car.



Click Here For The Original Source.

——————————————————–

..........

.

.