Kaspersky experts discovered a virus capable of infecting Android-based car multimedia centers
Read more
Olhar Digital
olhardigital.com.br

Kaspersky experts discovered a virus capable of infecting Android-based car multimedia centers

Specialists at Kaspersky have identified the first virus specifically designed to infect multimedia systems in cars that use the Android operating system. This malware was targeted at models utilizing software from the Chinese company DoFun, which is part of Shenzhen Driving Control Technology.

It is important to note that the virus was not tied to any specific car brand; instead, it affected 'universal multimedia centers with Android and customized systems that use the DoFun software infrastructure and theme store,' explained technology specialist Leonardo La Rosa in an interview with Olhar Digital.

This operation was attributed to cybercriminals associated with the BADBOX and MoYu Group networks. According to the specialist, these groups are 'operators specializing in mass infection of vulnerable Android ecosystems—such as inexpensive TV boxes, and now car manufacturers' multimedia centers using solutions from the Chinese company DoFun.'

The developer of this software was notified by the cybersecurity service researchers. According to Kaspersky, the discovered vulnerabilities have been patched, theoretically closing this incident. However, this has paved the way for potentially more serious future incidents.

The virus infected the multimedia centers without the user noticing. Kaspersky reported that it utilized an existing resource within the vehicle's system. As AI specialist Stefano Levorato clarified in an interview with Olhar Digital, 'this does not mean that someone automatically gained access to control, braking, or acceleration of the vehicle.'

In practice, the infected media center became slower and consumed more internet data, which might seem like a minor inconvenience. Nevertheless, La Rosa emphasized: 'The main threat lies in the concept of an 'open door.' '

When malicious software installs a backdoor in the vehicle's central unit, the device begins responding to remote commands. The director warns: 'A criminal may decide to sell access to this connection to other cybercriminals so they can mask digital crimes using your car's IP address.'

Furthermore, more aggressive modules could be introduced in the future, capable of collecting personal data, associated accounts, and the driver's navigation history.

The real danger lies not in the current symptom but in the bridge built for tomorrow's attack.

Levorato, who is a co-founder of the Brazilian Society of Innovation (SBI) and National Director of the Global Innovation Institute (GInI) in Brazil, highlights another aspect: 'We must be very careful not to turn possibility into fact. To our knowledge, there is no evidence that the malware reached critical vehicle systems.'

He notes that there is only potential for evolution within the compromised environment. In Levorato's opinion, to reach systems such as braking, steering, or the powertrain of a modern car, a hacker would still have to overcome other security barriers.

For La Rosa, this case marks a turning point because, according to him, it officially signals the transition of botnets from the realm of computers and smartphones into the field of automotive IoT. He observes: 'Criminals have realized that modern cars have turned into large smartphones on wheels, but they often lack the same maturity in terms of security and update cycles as a flagship mobile phone.'

La Rosa continues, pointing out that 'this is a paradigm shift. Hackers have noticed that there is an ocean of underutilized and poorly protected computing power in garages all over the world.'

The specialist also points out that 'as automakers increasingly integrate infotainment systems with vehicle sensors and controls for convenience, the attack surface is only increasing.'

He concludes: 'The automotive market must learn to treat firmware and software with the same level of security as mechanical engineering.'

La Rosa also emphasizes that this case of a botnet in multimedia centers serves as a kind of 'Proof of Concept' for cybercriminals. It demonstrated that attackers were able to penetrate and utilize light and the internet.

'The real danger in the future is that, once inside, they will start trying to open doors to rooms where locks, geolocation, sensors, and core vehicle systems are located.'

For Levorato, this case 'does not necessarily create a path for similar or worse attacks.' It merely demonstrates that this type of attack exists and can be implemented on a large scale.

The main significance of this episode lies not so much in the damage caused by this specific malware, but in the warning it carries regarding the new technological environment of the automobile.

What to do in the face of this threat? La Rosa advises: 'The first piece of advice is always to keep the car's software up to date and prefer official updates provided by the manufacturer or dealer.'

Another tip from the specialist: 'Absolutely avoid rooting procedures, installing parallel firmwares, or downloading applications from sources other than official stores in an attempt to unlock features in the multimedia center.'

The director also recommended: 'If you use a universal or modified Android infotainment system, avoid connecting your most confidential accounts or conducting financial transactions through it.'

Finally, pay attention to operational signs: if the car screen starts showing unusual freezes, excessive and unexplained internet traffic consumption, or strange behavior when starting the car, contact the brand's technical support to check the system's integrity.

Levorato adds that 'responsibility cannot be entirely shifted to the consumer. There is part of the car system that the owner simply cannot control.'

In his view, fixing firmware vulnerabilities, integrating vehicle systems, security of updates, and threat monitoring depend on automakers and their suppliers.

Similar stories

New virus infects Android car multimedia centers without the driver's knowledge
Read more
autopapo.com.br

New virus infects Android car multimedia centers without the driver's knowledge

Even if the driver is vigilant about cyber risks—avoiding suspicious links, not connecting unknown flash drives, and not using pirated applications—their car's multimedia center can become part of an online criminal network.

This was reported by an analysis from Kaspersky concerning malware campaigns specifically designed to infect Android-based multimedia systems.

According to researchers, the attack utilized the device's own update mechanism, which is intended to ensure system security. After installation, the malicious program ran in the background, showing no icons or warnings on the screen, thus paving the way for subsequent loading of other components.

The analysis revealed functions that allowed collecting technical device data, such as model, screen resolution, connected Wi-Fi network, and MAC address. Furthermore, the code engaged in advertising fraud and, more importantly, turned the central unit into a proxy server through which traffic from third-party users passed, integrating the hardware into a botnet—a remotely controlled network of devices.

The activity was highly confidently attributed to the criminal group MoYu, associated with the BadBox botnet, which had previously been involved in attacks on other Android devices.

Fortunately, there is no evidence that the attackers gained control over the vehicle's steering wheel, brakes, or accelerator; the target was specifically the multimedia system and its internet connection, not the critical vehicle systems.

Kaspersky also did not disclose a list of affected vehicles, and having Android multimedia or using Android Auto does not inherently mean vulnerability. The infected centers used software from the Chinese company DoFun, which supplies solutions to both automakers and aftermarket installers.

This second segment is very common in Brazil, where replacing the factory radio with a universal Android multimedia unit has become commonplace, often occurring in accessory stores without a guarantee that the software developer will continue to release fixes. Some of these devices have their own connectivity, including a SIM card, which increases the risk.

DoFun was notified and stated that it has eliminated the discovered vulnerability, making system updates the primary defense measure. It is also recommended to install software only from official sources, avoid APK files and alternative stores, check whether the manufacturer provides security updates, and contact technical support if the central unit starts displaying unexpected advertisements, freezing without reason, or consuming an unusually large amount of data.

Popular