Malware Takes the Wheel: Kaspersky Finds First Car Head Unit-Specific Attack
ID: a5fe15c6-052f-5f41-9fa4-076a66419f83
STIX ID: report--a5fe15c6-052f-5f41-9fa4-076a66419f83
Feed Name: Security Ledger
Kaspersky researchers found Android malware propagating via the legitimate TWCore update mechanism on DoFun automotive infotainment head units; the multi-stage infection chain installs ad-fraud and a reverse-proxy module ('zhima') to recruit head units into a residential proxy botnet attributed to the MoYu Group. The report links this case to wider trends—FBI and Black Lotus Labs warnings—about large-scale proxy botnets abusing IoT and SOHO devices and highlights that connected vehicle systems can be co-opted as general-purpose malicious infrastructure rather than being targeted for direct vehicle control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
