Android Car Head Units Hijacked via Malicious OTA Updates, Enlisting Devices in BADBOX Proxy Botnet
What Happened – Kaspersky discovered a new Android‑based malware that is delivered through the built‑in over‑the‑air (OTA) updater of aftermarket car head units. The updater (TWCore) accepts a remote instruction to install unsigned apps, allowing the payload to turn the infotainment device into an ad‑fraud proxy and a node in the BADBOX botnet.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a supply‑chain / OTA‑update control gap that SOC 2 Change Management (CC6.1) and System Operations (CC7.1) controls are designed to detect and evidence.
- Continuous monitoring of third‑party firmware and immutable code‑signing logs provides the audit trail needed to prove due diligence to auditors.
- Mapping the OTA process to Verisq’s Control Mapping capability gives you real‑time evidence that update controls remain enforced across the device lifecycle.
Who Is Affected – Aftermarket automotive infotainment manufacturers, OEMs that integrate third‑party head‑unit software, and any service providers that rely on SIM‑enabled vehicle telematics.
Recommended Actions
- Inventory all OTA update mechanisms and map them to SOC 2 change‑management controls.
- Enforce cryptographic signing for every firmware/app package and require immutable logs of signature verification.
- Deploy continuous monitoring of OTA traffic and update‑server communications; retain logs as audit evidence.
- Conduct a vendor‑risk review of the firmware supplier (DoFun) and require attestations of secure build processes.
Source: Help Net Security
Technical Notes – The malicious chain starts with TWCore, a legitimate analytics/updater app that polls a broker at cardoor.cn. A Boolean flag (installNotExists) lets the attacker push arbitrary APKs. The dropper (JarService) loads a loader, which contacts a C2 server, receives one of seven payload variants, and then reports device details (screen resolution, MAC, Wi‑Fi SSID) every 90 minutes. No CVE is cited; the weakness is the unchecked OTA install capability.
Source: Help Net Security