DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Malware infects Android-based automotive head unit firmware

Quality: 8/10 Relevance: 9/10

Summary

Kaspersky Securelist analyzes Android head-unit malware that uses the device update mechanism to install a multi-stage downloader, ultimately forming a proxy botnet. The report attributes the activity to the MoYu Group (BADBOX) and documents Stage 1 JarService, Stage 2 loader, and Stage 3 zhima modules, with indicators of compromise and IPC artifacts. This highlights the growing risk of embedded automotive devices being targeted by sophisticated malware.

🚀 Service construit par Johan Denoyer