Experts discover new vulnerability: malware begins attacking car multimedia centers
Read more
Olhar Digital
olhardigital.com.br

Experts discover new vulnerability: malware begins attacking car multimedia centers

Researchers from Kaspersky have identified the first documented campaign of malware specifically designed to infect vehicle multimedia systems. This threat was discovered in June 2026 and utilizes a hidden multi-stage loader to install malware onto Android-based automotive systems.

The criminals' goals include conducting advertising fraud, using multimedia centers as intermediaries for malicious internet activity, and committing other criminal acts. According to Kaspersky, this campaign is the first documented case where malware infects a car's multimedia center through an infection chain specifically developed for these systems.

Researchers believe this activity may be linked to MoYu Group, a group associated with the BadBox botnet—a network of devices that can be remotely controlled by criminals. In the case analyzed by Kaspersky, the malware reached the devices through a vulnerability in the system responsible for updating the center's applications.

This mechanism is used in various models and was developed by DoFun. Its function is to automatically download necessary software for the center to operate. Criminals exploited this process to inject JarService—a program capable of installing other malware unnoticed by the driver. Although the source of the attack has not yet been determined, the company responsible for the system was notified of the vulnerability and has fixed the issue.

The malware was installed as a regular application but had no interface and ran in the background. Thus, the user did not need to interact with the program, and they might not have noticed the compromise of the center.

Kaspersky identified nine different commands implemented by the attackers. Furthermore, the criminals obtained information about the infected device, including screen resolution, device model, connected Wi-Fi network ID, and the MAC address used to identify the device on the network. This data allowed the campaign organizers to gather intelligence on the compromised hardware and manage various functions of the malware.

Additional Information

During the investigation, Kaspersky found signs of a connection between the campaign against automotive centers and MoYu Group, a group linked to the BadBox botnet. The comparison was made with previous activity targeting internet-connected televisions. Researchers also identified common technical elements between the panel used for botnet administration and home proxy services named PXYEDGE and ProxyForU.

BadBox is a botnet consisting of compromised Android devices, including streaming TV devices, smartphones, and tablets. Criminals use hidden access points, known as backdoors, to conduct advertising fraud, data theft, and use home networks as transit points for illegal internet traffic.

The discovery of a campaign targeting multimedia centers expands the range of Android devices that can be used in such operations. Fabio Marenghi, lead security researcher at Kaspersky, states that groups associated with BadBox continue to carry out malicious activities even after efforts by specialists and authorities to dismantle the botnet.

Marenghi stated: "Despite the efforts of cybersecurity specialists and authorities to dismantle the BadBox botnet, individual agents associated with it continue to carry out malicious activities and infect devices worldwide."

According to the researcher, the methods of spreading this type of malware are becoming increasingly diverse, including pre-installed backdoors and compromised IPTV applications. However, in the case of automotive centers, criminals used a different strategy: they exploited the legitimate software update function of the system application to distribute the malware.

Marenghi noted: "Attackers are actively conquering new platforms. This malware is the first malicious application specifically targeting vehicle multimedia centers through an infection chain specifically designed for these automotive systems."

For the researcher, this incident underscores the necessity of strengthening the protection of automotive platforms against malware. He concluded: "This serves as a warning that modern automotive platforms urgently require robust protection against malware."

Popular