Urgent.News

What's breaking now, across thousands of outlets.

Tech

Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet

Kaspersky discovers Android malware targeting car head units through compromised updates.

Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet

Hackers have allegedly infiltrated car head units through trusted software updates, potentially turning them into part of a botnet, according to security firm Kaspersky. This marks the first known instance of malware specifically designed for vehicle head units, which are increasingly being targeted in Android malware campaigns.

The attack vector originates from TWCore, an app typically responsible for software updates and analytics, which attackers hijacked using a dropper called JarService. Once installed, the malware operated silently in the background without displaying any visible interface. It was able to collect device information such as display resolution, model, Wi-Fi network identifier, and MAC address, and execute remote commands for displaying ads and fraudulently collecting data.

The malware is believed to be linked to the MoYu Group, a threat actor associated with the BadBox botnet, which previously spread through legitimate update mechanisms. The attack highlights the growing vulnerability of connected vehicle systems, which often rely on Android-based head units that lack robust security measures. Despite the lack of sensitive personal data stored directly on these devices, their constant connectivity and integration with navigation services make them an attractive target for cybercriminals.

Kaspersky has notified the vendor about this issue, which they claim has been resolved across most affected devices. However, the full extent of this particular campaign and whether other head unit manufacturers are similarly exposed remain unclear.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

VMware Appliance OVF Properties update through CLI

This article is to update VMware appliance ovf properties through command line. Sometimes we cannot access VC and only can access VMs through ESX UI.

  • Update VMware appliance OVF properties via CLI when Virtual Center access is unavailable.
  • Log in as root, navigate to VM scripts folder, and execute ovfenv command.
  • Modify NTP server details with update-ntpserver.sh script, then reboot VM.

More from Monday 24 August →