New virus infects Android car multimedia centers without the driver's knowledge
Read more
AutoPapo
autopapo.com.br

New virus infects Android car multimedia centers without the driver's knowledge

Even if the driver is vigilant about cyber risks—avoiding suspicious links, not connecting unknown flash drives, and not using pirated applications—their car's multimedia center can become part of an online criminal network.

This was reported by an analysis from Kaspersky concerning malware campaigns specifically designed to infect Android-based multimedia systems.

According to researchers, the attack utilized the device's own update mechanism, which is intended to ensure system security. After installation, the malicious program ran in the background, showing no icons or warnings on the screen, thus paving the way for subsequent loading of other components.

The analysis revealed functions that allowed collecting technical device data, such as model, screen resolution, connected Wi-Fi network, and MAC address. Furthermore, the code engaged in advertising fraud and, more importantly, turned the central unit into a proxy server through which traffic from third-party users passed, integrating the hardware into a botnet—a remotely controlled network of devices.

The activity was highly confidently attributed to the criminal group MoYu, associated with the BadBox botnet, which had previously been involved in attacks on other Android devices.

Fortunately, there is no evidence that the attackers gained control over the vehicle's steering wheel, brakes, or accelerator; the target was specifically the multimedia system and its internet connection, not the critical vehicle systems.

Kaspersky also did not disclose a list of affected vehicles, and having Android multimedia or using Android Auto does not inherently mean vulnerability. The infected centers used software from the Chinese company DoFun, which supplies solutions to both automakers and aftermarket installers.

This second segment is very common in Brazil, where replacing the factory radio with a universal Android multimedia unit has become commonplace, often occurring in accessory stores without a guarantee that the software developer will continue to release fixes. Some of these devices have their own connectivity, including a SIM card, which increases the risk.

DoFun was notified and stated that it has eliminated the discovered vulnerability, making system updates the primary defense measure. It is also recommended to install software only from official sources, avoid APK files and alternative stores, check whether the manufacturer provides security updates, and contact technical support if the central unit starts displaying unexpected advertisements, freezing without reason, or consuming an unusually large amount of data.

Similar stories

Experts discover new vulnerability: malware begins attacking car multimedia centers
Read more
olhardigital.com.br

Experts discover new vulnerability: malware begins attacking car multimedia centers

Researchers from Kaspersky have identified the first documented campaign of malware specifically designed to infect vehicle multimedia systems. This threat was discovered in June 2026 and utilizes a hidden multi-stage loader to install malware onto Android-based automotive systems.

The criminals' goals include conducting advertising fraud, using multimedia centers as intermediaries for malicious internet activity, and committing other criminal acts. According to Kaspersky, this campaign is the first documented case where malware infects a car's multimedia center through an infection chain specifically developed for these systems.

Researchers believe this activity may be linked to MoYu Group, a group associated with the BadBox botnet—a network of devices that can be remotely controlled by criminals. In the case analyzed by Kaspersky, the malware reached the devices through a vulnerability in the system responsible for updating the center's applications.

This mechanism is used in various models and was developed by DoFun. Its function is to automatically download necessary software for the center to operate. Criminals exploited this process to inject JarService—a program capable of installing other malware unnoticed by the driver. Although the source of the attack has not yet been determined, the company responsible for the system was notified of the vulnerability and has fixed the issue.

The malware was installed as a regular application but had no interface and ran in the background. Thus, the user did not need to interact with the program, and they might not have noticed the compromise of the center.

Kaspersky identified nine different commands implemented by the attackers. Furthermore, the criminals obtained information about the infected device, including screen resolution, device model, connected Wi-Fi network ID, and the MAC address used to identify the device on the network. This data allowed the campaign organizers to gather intelligence on the compromised hardware and manage various functions of the malware.

Additional Information

During the investigation, Kaspersky found signs of a connection between the campaign against automotive centers and MoYu Group, a group linked to the BadBox botnet. The comparison was made with previous activity targeting internet-connected televisions. Researchers also identified common technical elements between the panel used for botnet administration and home proxy services named PXYEDGE and ProxyForU.

BadBox is a botnet consisting of compromised Android devices, including streaming TV devices, smartphones, and tablets. Criminals use hidden access points, known as backdoors, to conduct advertising fraud, data theft, and use home networks as transit points for illegal internet traffic.

The discovery of a campaign targeting multimedia centers expands the range of Android devices that can be used in such operations. Fabio Marenghi, lead security researcher at Kaspersky, states that groups associated with BadBox continue to carry out malicious activities even after efforts by specialists and authorities to dismantle the botnet.

Marenghi stated: "Despite the efforts of cybersecurity specialists and authorities to dismantle the BadBox botnet, individual agents associated with it continue to carry out malicious activities and infect devices worldwide."

According to the researcher, the methods of spreading this type of malware are becoming increasingly diverse, including pre-installed backdoors and compromised IPTV applications. However, in the case of automotive centers, criminals used a different strategy: they exploited the legitimate software update function of the system application to distribute the malware.

Marenghi noted: "Attackers are actively conquering new platforms. This malware is the first malicious application specifically targeting vehicle multimedia centers through an infection chain specifically designed for these automotive systems."

For the researcher, this incident underscores the necessity of strengthening the protection of automotive platforms against malware. He concluded: "This serves as a warning that modern automotive platforms urgently require robust protection against malware."

New virus alters Pix QR Code in online purchases in Brazil, diverting consumer funds
Read more
olhardigital.com.br

New virus alters Pix QR Code in online purchases in Brazil, diverting consumer funds

A new type of malware compromised 90 virtual stores in Brazil, altering Pix codes in real time during online purchase transactions. The cybersecurity company Kaspersky confirmed the occurrence of the fraud after identification by the independent researcher known as “eremit4”.

According to Folha, this malicious code modifies both the QR Code and the Copy and Paste Pix functionality at the exact moment the end consumer finalizes the purchase. The amounts are then redirected to accounts controlled by scammers, without the buyer noticing any visual indication of irregularity.

The attack specifically targets e-commerce websites that use the Magento platform. When the customer generates the payment to complete their order, a script replaces the original QR Code with a fraudulent code managed by the criminals. Since this modification occurs internally on the website itself, the buyer does not detect any anomaly.

The nature of the attack

The researcher eremit4 nicknamed this operation “the new Brazilian magecart,” alluding to the traditional fraud method used to steal credit card information. Furthermore, if the customer opts for payment via credit card, the same malware has the ability to capture the data for subsequent fraud. In this scenario, the merchant receives the payment normally, but the customer is vulnerable to their card being cloned.

Since the attacker infects the website and not the victim's device, the potential damage is significantly greater, affecting all store customers. Fabio Assolini, director of the Kaspersky investigation team in Latin America, commented on the situation for Folha.

Security and recovery measures

It is crucial for the consumer to identify the fraud quickly to have a chance of recovering the money. The Special Return Mechanism (MED) of Pix allows tracking the transaction for a maximum of five transfers, according to Assolini. However, criminals can disperse the amount across several shell accounts within a few hours, which complicates the recovery of funds.

Assolini stressed that “Criminals know that the limit of traceable transfers is five passes. The MED is valid when the person notices quickly.” Although the consumer has up to 80 days to request the MED, the Central Bank advises that the dispute should be registered even if recovery is not guaranteed, as this helps financial institutions map the accounts used in fraudulent schemes.

Since the payment alteration shows no visible signs, the consumer's main line of defense lies in meticulously verifying the data before authorizing the transfer. Merchants affected by the virus noted an increase in order cancellations. Some opted to disclose the CNPJ and company name so the customer could confirm the Pix beneficiary, while others implemented the use of external payment platforms.

Prevention recommendations

To reduce the risk of future infections, Kaspersky suggests keeping the Magento platform always updated, using strong and unique passwords for administrative access to the site, and performing continuous monitoring with quality software. The code responsible for the attack may be disguised in obfuscated sections, making the detection of malicious behavior difficult. This same threat can also steal card data when the customer chooses this payment method.

If someone identifies a fraudulent Pix, they must access the Pix section in the banking application, select the “Dispute Pix” option, and declare that it is a scam or fraud. The involved accounts may remain blocked for up to 11 days during the investigation process, and any refund will depend on the availability of funds and the analysis of the financial institutions.

Popular