• Android car systems abused by hackers to launch new malware that

    From TechnologyDaily@1337:1/100 to All on Tuesday, August 25, 2026 14:15:24
    Android car systems abused by hackers to launch new malware that pulls
    devices into a hidden proxy network

    Date:
    Tue, 25 Aug 2026 13:10:07 +0000

    Description:
    Crooks found a flaw in an analytics app and used it to deploy malware to
    cars' infotainment systems.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Kaspersky found Android malware abusing DoFun car head units via TWCore updates Multistage attack installs loaders and reverse proxy, aiming to build a botnet of connected cars
    Campaign attributed to MoYu Group; DoFun patched vulnerabilities after disclosure Weve seen botnets comprising cameras and DVRs, weve even seen botnets comprising smart fridges and digital frames, but weve never seen botnets comprising automobile infotainment systems . First time for everything.

    Earlier this week, security researchers Kaspersky warned about finding a
    brand new Android malware targeting the cars head unit. The victim seems to
    be a Chinese manufacturer called DoFun. Head units from this manufacturer, built on Android, are running an app for analytics and software updates
    called TWCore. According to Kaspersky, the attackers abused TWCores update mechanisms, instructing it to download a malicious APK. This malware is then placed in the apps cache directory and installed by the legitimate
    com.tw.core package. Latest Videos From TechRadar Watch full video here: No active campaigns The researchers said this was a multi-stage attack. In the first stage, a tiny dropper with no user interface gets deployed. It decrypts embedded data, and extracts the information it needs for stage two. In the next stage, the loader contacts the attackers server and gets instructions about stage 3, which can be different things, from deploying additional malware, to running the zhima reverse proxy.

    Despite its multifunctional nature, Kaspersky believes that the true goal of the campaign is to assimilate the cars into a botnet. Some cars come with a SIM slot and are connected to the internet 24/7. It is probably not an exaggeration to say that cars just might be the perfect devices for a malicious botnet. You may like Even connected car head units are being targeted by hackers now experts warn in-car systems are at risk of being hijacked into a botnet Experts warn hackers are hiding malware inside
    Google's own ad systems here's what we know Experts warn Claude feature hijacked by hackers to launch major malware campaign

    Kaspersky attributed the campaign to MoYu Group, a threat actor known for building malicious botnets based on Android devices. In the past, this group was observed building the BadBox botnet out of Android smartphones, tablets, streaming devices, and other internet-connected hardware.

    The researchers notified DoFun of their findings, and the vulnerability was quickly fixed: "We notified the vendor about the distribution scheme, and
    they subsequently reported fixing the security issues," the researchers said. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    Via The Record The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/android-car-systems-abused-by-hackers-t o-launch-new-malware-that-pulls-devices-into-a-hidden-proxy-network


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)