- Pandora Malware Discovery: Security researchers identified a supply-chain attack where Android-based car head units and TV boxes are infected with the Android.Voit.1 (Pandora) malware.
- Botnet Exploitation: Compromised devices are converted into proxy servers that facilitate ad fraud and provide anonymity for cybercriminals by routing traffic through the owner’s IP address.
Security Researchers Identify Pandora Malware
Security researchers at Dr.Web identified a supply-chain attack targeting Android-based car head units and TV boxes. The malware, identified as Android.Voit.1 (Pandora), is often embedded directly into the system partition of the device firmware. This positioning allows the malicious code to remain persistent on the hardware. By focusing on specific hardware vulnerabilities, this campaign ensures control over user environments from the moment the device is powered on.
Infection via Device-Update Applications
The infection mechanism frequently exploits a “legitimate” device-update app to download and execute the malicious payload. By using an application that users expect to manage system software, the malware can successfully bypass initial scrutiny. Data indicates that budget-friendly, unbranded Android head units purchased from third-party marketplaces are at the highest risk for pre-installed malware. Unlike standard systems that might use Android Pulse for legitimate system functions, these unbranded units often ship with compromised firmware.
Conversion into Proxy Botnets
The primary goal of the botnet is to facilitate ad fraud and provide anonymity for cybercriminals through a residential proxy network. Once the Pandora malware is active, compromised devices are turned into proxy servers. This allows hackers to route malicious traffic through the owner’s IP address, masking the true origin of the activity. According to the Dr.Web Report, this enables a wide range of unauthorized actions under the guise of a legitimate home or vehicle connection.
The scale of these proxy botnets highlights the risks associated with the secondary hardware market. Because the malware is embedded at the firmware level during the supply chain process, the devices are often infected before they reach the consumer. This infrastructure provides a layer of anonymity that cybercriminals use to shield their activities from standard security tracking.
