安全研究人员在2026年6月发现了一种针对Android车机头单元的新型恶意软件,这是首例有记录的此类攻击1。该恶意软件通过DoFun头单元固件中的合法更新功能进行传播,采用多阶段感染链:从TWCore应用开始,经由JarService dropper和恶意加载器,最终演变为clicker和反向代理加载器1。
安全研究人员以高度置信度将该恶意软件归因于与BADBOX僵尸网络相关的MoYu Group1。这个多阶段下载器的最终目的是执行广告欺诈活动并创建代理僵尸网络1。根据分析,该恶意软件默认每90分钟与命令控制服务器进行一次POST请求通信,研究时检测到的最新配置版本为3.821。
Security researchers discovered a new Android malware in June 2026 that spreads through the built-in firmware updater of Android-based automotive head units, marking the first documented malware infection chain targeting such devices 1. The multi-stage downloader ultimately aims to conduct ad fraud and establish a proxy botnet, and has been attributed with high confidence to the MoYu Group, an actor linked to the BADBOX botnet 1.
The infection chain begins with the TWCore application, progressing through a JarService dropper to a malicious loader that eventually deploys either a clicker or reverse proxy loader 1. The malware is distributed through the legitimate update functionality of DoFun head units' firmware, exploiting a trusted system mechanism to gain persistence on affected devices 1. Once installed, the malware establishes command-and-control communication, with default POST requests sent every 90 minutes 1. At the time of research, the malware configuration had reached version 3.82 1.
评论
还没有评论,欢迎留下第一条。