Cars were originally designed to facilitate human movement, but over time, functions related to entertainment and other lifestyle needs have been integrated into them. This has led to the addition of numerous new features in vehicles that are potentially vulnerable to hacking.
A malicious program has been discovered that is considered the first malware targeting automotive infotainment systems. This was reported by the threat research team at Kaspersky Security.
According to Kaspersky, this is the first documented malicious code that specifically attacks car infotainment units by exploiting their automatic update function. However, for this attack to be successful, the malware requires several sequential steps.
Once the system was compromised, attackers could use it in various ways. The most common is ad fraud, where advertisements are displayed in the background on the user's screen without being noticed. These ads lead to rapid data consumption. Such a threat can affect both factory-installed and third-party Android-based devices.
This malware was found in the infotainment units of the Chinese manufacturer DoFun. This company develops its own Android-based operating system and cloud applications used in 30 million cars worldwide. The malware was distributed through DoFun's over-the-air (OTA) update mechanism.
Kaspersky notes that the vulnerability exploited by this malware has already been fixed by releasing a patch. The constant internet connection feature in many automotive information systems makes them an easy target for such malware.
In the case of DoFun, the TWC module, which the manufacturer uses for analytics collection and software updates, was compromised. Attackers managed to inject their malicious code into this process, allowing them to easily deliver it to the affected units. This malware was created to evade detection.
It operated exclusively in the background, and the user received no notification about it. Furthermore, this malware had the capability to send unique identifying information, display fake advertisements, and download and execute software. This means that after penetrating the vehicle's infotainment system, a hacker could upload any application there.
