Archive for August 24, 2026

Supply chain attack infects Android car systems with botnet malware

Posted in Commentary with tags on August 24, 2026 by itnerd

Kaspersky researchers uncovered a supply chain attack infecting Android-based car head units with malware designed for ad fraud and proxy botnet activity.

The malware was distributed through the built-in updater of TWCore, a legitimate system application installed on head units from Chinese automotive technology provider DoFun. Researchers said this is the first documented malware infection chain specifically designed to target automotive head units.

The attack uses a three-stage infection chain, beginning when the legitimate updater downloads a malicious APK. Once installed, additional malware components are retrieved that can generate fraudulent advertising activity and turn the vehicle’s internet connection into a proxy for other traffic. 

The threat is imminent. Today’s notice of the critical Keycloak Password Reset Flaw (CVE-2026-18963, CVSS 9.1) exposes thousands of enterprise identity servers to risk of complete, unauthenticated takeover.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “MoYu Group, the same actor behind BADBOX infections on cheap Android TV set-top boxes, expanded to car dashboards because to a residential proxy operator, any Android device with a Subscriber Identity Module (SIM) card is just inventory.

   “DoFun’s TWCore updater accepts instructions from a Message Queuing Telemetry Transport (MQTT) broker and includes a flag called installNotExists that lets the server push entirely new applications to the device without human approval. The attackers pushed malware through this privileged deployment channel exactly as it was designed to work.

   “The zhima proxy module on these head units ties back to residential proxy services PXYEDGE and ProxyForU, both connected to MoYu Group’s broader infrastructure. Compromised vehicles are being sold as proxy endpoints to whoever pays. A car sitting in a parking lot becomes someone else’s exit node, routing traffic through a cellular connection the vehicle owner pays for.

   “Every original equipment manufacturer (OEM) sourcing Android-based head units from third-party firmware providers should be asking who audited the update channel before it shipped. Arbitrary code delivery already works through loadlib2, while loadlib and loadlib3 command paths were not fully implemented at the time of analysis. The proxy botnet is the current monetization model; the underlying access gives the operator considerably more capability than proxying traffic.”

John Strand, Owner, Black Hills Information Security, Inc.:

   “If I’m looking at the overall trend of attacks we’ve been seeing lately, this fits right in. Supply chain attacks, malicious NPM packages, and similar techniques are increasingly showing up in some of the more advanced and interesting attacks. I’m not necessarily talking about ransomware here. I’m talking about attackers deliberately targeting areas that create blind spots for information security teams.

   “For years, so much of information security has been focused on endpoints and EDR. More recently, organizations have started expanding that focus into cloud and identity security. That’s good, but attackers are moving into technologies that many traditional security stacks simply weren’t designed to monitor.

   “Supply chain attacks are a perfect example. So is Android malware targeting head units used by automobile manufacturers. Most people aren’t running EDR on their car.

That sounds funny, but it highlights a serious problem.

   “Attackers are finding technologies that fall outside the visibility of traditional security tools. Once they get into those environments, they have an opportunity to propagate, establish persistence, and potentially remain undetected for long periods of time. The problem isn’t necessarily that security teams aren’t paying attention. In many cases, the technology they’ve invested in simply doesn’t support these systems.”

SOCRadar Uncovers AI-Powered PhaaS “AnonyMousKIT” Stealing Apple IDs/Passwords

Posted in Commentary with tags on August 24, 2026 by itnerd

Today, SOCRadar’s Threat Research Unit (STRU) published new research about AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) platform built to steal the Apple ID and passcode needed to unlock a stolen iPhone. A basic coding mistake in its backend exposed the whole operation — developer, resellers, and operators.

Apple’s Activation Lock turns a stolen iPhone into scrap unless someone gets the owner’s Apple ID and passcode. AnonyMousKIT turns that into a subscription service: load a stolen device’s details into the panel once, and it works through email, SMS, WhatsApp, a recorded call, and an AI phone call on its own until the owner responds. Two exposed relative file paths handed STRU months of production logs, tracing this one storefront back to a shared codebase running on 506 domains under 168 brand names.

What STRU found:

  • Device-led lures: messages cite the phone’s real Apple model number, like iPhone16,2, and its live Find My location pulled straight off the stolen device.
  • An AI voice agent posing as Apple Support: a rented commercial voice AI, scripted as “Alice from Apple Support” in English, Spanish, and Portuguese, talks victims into reading out their passcode live, then walks them to the phishing link.
  • A reseller network behind the rebrands: the shared codebase ties 506 domains and 168 storefronts together; scanning that family found 30 still-active backends across 42 domains.

The color detail:

  • Ten cents a call: 200 AI voice calls, 90% to Brazil, cost the operator $19.24 total — cheap enough that targets don’t need to be chosen carefully.
  • The bait doesn’t even work: the panel’s four “free” jailbreak tools only run on chips up to the iPhone A11, while 92.7% of targeted devices are A12 or newer.
  • One buyer, three storefronts: an identical setup-check email (26 log lines, every time) shows up in 12 of 24 exposed backends, and three storefronts launched in the same second on April 10, 2026, sharing the same Gmail relay accounts.

The defender takeaway:

  • The tell is the ask: no legitimate Apple or IT support team will ever call and request a passcode or 2FA code out loud.
  • Not just a consumer problem: AnonyMousKIT alone emailed lures to 27 South African government addresses and a local university — a compromised personal Apple ID can still expose corporate Keychain credentials.
  • Still running as of our last collection date, and SOCRadar continues tracking the wider family.

To view the full research, IOCs, and ATT&CK mapping, see the just-published report  Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain

UK power plant outage shows why four days of downtime matters more than attribution

Posted in Commentary with tags on August 24, 2026 by itnerd

A UK power plant reportedly went dark for four days in July after a cyberattack linked to Iranian hackers, but the story only surfaced this week, and the UK government still hasn’t confirmed or denied the incident or the attribution

The government said that at no point was there a risk to the UK’s energy system, but the Department for Energy Security and Net Zero (DESNZ) has contacted power companies to advise them about the risk of cyber attacks.

The Telegraph reported that the attack, which took place last month, was carried out by hackers affiliated to the Iranian regime.

For security reasons, neither the government nor the National Cyber Security Centre, which deals with attacks on critical infrastructure, would give further details of the site affected. However this was not an attack on an essential service such as a large power station.

Josh Picolet, VP of Detection & Analysis, Team Cymru

“State-linked activity against critical infrastructure tends to follow patterns that outlast any single incident, and the four-day recovery window here is the detail worth studying closely. That length of disruption usually means the attacker had dwell time inside the environment before detection, which points to a gap in visibility rather than a one-off failure.

It’s worth noting the UK government has neither confirmed nor denied the incident or the attribution to Iran-linked actors, so defenders should treat the public reporting with appropriate caution while still taking the operational lesson seriously. Regardless of formal attribution, the pattern is consistent with what we’ve tracked from Iran-affiliated groups against critical infrastructure across the US, Israel, the Gulf, and now Europe this year. Smaller operators in particular need intelligence that surfaces staging and pre-positioning activity, not just indicators tied to a confirmed actor, because the next facility targeted may not get four days of warning before impact.”

Justin Beals, CEO & Founder, Strike Graph

“Four days of downtime at a critical infrastructure facility is not a technical failure. It’s a governance failure. Somewhere in that plant’s compliance program, a control existed on paper that didn’t hold up in practice, and nobody caught the gap until an adversary found it first.

This is the same story we keep seeing across sectors. Organizations treat security posture as something you attest to once a year, not something you verify continuously. A point-in-time audit tells you a plant was secure on the day someone checked. It tells you nothing about the day the attacker showed up.The UK has thousands of smaller energy assets like this one, and most of them are operating on the same annual-attestation model. If this attack is repeatable, and there’s no reason to think it isn’t, the operators still relying on periodic reviews instead of continuous monitoring are the ones who will be explaining a multi-day outage to their regulator next.”

Expect more state sponsored actors to do hacks like this. Because there’s likely more of this out there that is under reported.

UPDATE: John Strand, Owner, Black Hills Information Security, Inc. Had This To Say:

   “This particular breach scares me, not necessarily because it happened in the United Kingdom, but because of how much further behind the United States power grid is compared to Europe. Modernization of the U.S. power grid has been painfully slow for a number of reasons, including legislative capture and the basic economics of how utilities make money. They make money from generating and selling power. They don’t necessarily make money from updating aging infrastructure.

   “Then there’s the interconnected nature of the U.S. power grid, with Texas being the notable exception. A relatively small problem at a substation can create ripple effects across multiple areas of the grid. That’s what makes this such a serious wake-up call. When you combine that interconnectedness with the incredibly slow pace of infrastructure modernization, especially across the power grid, I’m very concerned. I think an attack like this could potentially have a far greater impact in the United States than what we’re seeing in Europe.”

Denis Calderone, CTO, Suzu Labs:

   “What has our attention here is not the size of the generator. A savvy attacker isn’t choosing targets based on grid capacity. They’re probing for the weakest point in the armor, and a facility small enough to fall below mandatory cyber reporting thresholds is exactly the kind of target that’s likely under-defended and overlooked.

   “Two weeks ago in Poland, a compromised wind farm became a direct bridge into a completely separate heating plant’s SCADA system through a shared cellular network. Different threat actor, different country, same playbook: find the overlooked facility, use it as a stepping stone. We’ve been tracking Iran-linked operations against Western critical infrastructure since April, and the pattern keeps escalating. PLCs targeted for operational disruption. Gas station fuel monitoring systems. Water systems across 12 US states in a single month. Five agencies flagged AI-generated tools targeting Siemens PLCs four days ago. And now a UK power facility goes dark for four days.

   “The victim became the victim because of poor hygiene. The advice here is the same as it ever was, because the exposure hasn’t changed. Take controllers off the internet. Change default credentials. Inventory every communication path, especially the integrator-installed remote access links and the backup channels that never made it onto a network diagram. But critical infrastructure operators need to be proactively hunting for these weaknesses and prioritizing remediation before an adversary does the discovery for them. The smaller satellite sites are often the ones that fall under the radar during security reviews, so make sure you look at everything. Small and overlooked is exactly what made this target attractive.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

   “There is a real and growing threat to critical infrastructure, however the way we talk about these incidents matters.

   “If this was genuinely a historic cyber-induced shutdown of a British power generator, then operators need to know what made it possible.  Was a PLC directly exposed to the Internet?  Was remote access compromised?  Did attackers manipulate the physical process, or did operators shut the plant down defensively after an IT compromise?  What control would have broken the attack chain?

   “Don’t tell me this was historic and then redact the history.

   “We can protect the identity of the victim and sensitive operational details while still publishing a sanitized technical account.  CERT Polska has shown what responsible disclosure can look like: explain the attack path, identify the class of failure, and give other operators something they can actually use to defend themselves.

   “The same caution applies to attribution.  “Iran-linked” is not the same thing as proving that the Iranian government directed the attack.  We should distinguish what happened to the plant, who conducted the intrusion, and by which nation state it was instructed.  Attribution in cyberspace is an analytical conclusion, not something you read off the source IP address.

   “The larger problem is that too many cyber incidents and near misses disappear into non-disclosure or tightly held incident reports.  One operator learns an expensive lesson while thousands of others are left to learn it again.  The point of incident reporting should not simply be counting attacks.  It should be making the next attack harder.

   “We keep sweeping these incidents and near misses under the rug when we should be dragging them into the light and learning from them.

   “If joint cybersecurity advisories can say what went wrong in Minnesota without handing attackers a blueprint, we should be able to tell operators what class of failure took a British peaking plant offline for four days.”

Seemant Sehgal, Founder & CEO, BreachLock

   “OT in power plants and water treatment facilities wasn’t designed with adversarial persistence in mind. The visible coordination across a UK facility and dozens of US water systems in the same window indicates that these environments are being mapped and tested well before the disruptive payload arrives. 

   “The teams running these facilities need to know which of their OT assets are reachable, how an attacker would move from IT into operational systems, and where their recovery dependencies sit, because it’s already too late to be asking those questions by the time the outage clock starts.”

SOCRadar Now Offered Through GuidePoint Security 

Posted in Commentary with tags on August 24, 2026 by itnerd

SOCRadar today announced a new reseller collaboration with GuidePoint Security, the leading cybersecurity solution provider that helps organizations make better decisions that minimize risk. The collaboration is designed to expand customer access to SOCRadar’s award-winning Extended Threat Intelligence platform through GuidePoint’s extensive network of enterprise and public sector customers. 

As organizations face increasingly sophisticated cyber threats, SOCRadar’s comprehensive threat intelligence capabilities and intelligence-driven approach, combined with GuidePoint’s proven advisory and integration expertise, enable customers to proactively identify, assess, and mitigate external risks before they impact business operations. 

SOCRadar is the pioneer of Agentic Threat Intelligence serving organizations across more than 150 countries. The company’s award-winning Agentic Threat Intelligence Platform delivers an industry-first early warning cyber risk detection and mitigation system to proactively identify and reduce external cyber threats before attackers can exploit them. The platform uniquely combines AI agents with one of the industry’s most comprehensive cyber intelligence ecosystems to continuously discover, investigate, and prioritize risks across the internet, deep web, dark web, social media platforms, third-party ecosystems, and exposed digital assets. Integrating Brand Protection and Attack Surface Management (ASM) through its XTI platform, SOCRadar helps customers defend against external threats like phishing, brand impersonation and ransomware, as well as account takeover, exposed credentials, supply chain risks, and emerging attacker activity. 

Android’s nude-scanning app keeps reinstalling itself – and Google is opening access to other developers 

Posted in Commentary with tags on August 24, 2026 by itnerd

Android users were shocked last year to find Android System SafetyCore installed on their devices without consent, silently “scanning” content. Google is now developing an API that makes the content classification functionality available to third-party apps.

Cybernews looked into what SafetyCore does, the new Content Safety Manager API, and whether malicious apps or spyware could abuse it to scan for sensitive images.

Key findings:

  • SafetyCore performs image classification on the device to prevent users from seeing nudity when they receive, send, or forward messages in Google Messages.
  • Google states that this feature doesn’t send identifiable data or any classified content or results to Google’s servers.
  • Android just introduced a new API for developers – Content Safety Manager. It uses the on-device content safety service to classify content and exposes this functionality to app creators.
  • The API can accept images but also other media types, and returns four broad types: allowed / warning / blocked / unclassified.
  • Google doesn’t have complete control over what third-party apps do with the data.
  • Combined with excessive permissions, a malicious app could abuse the content-scanning capability to inspect large amounts of user content. This could lead to privacy-invasive profiling, or much worse – exfiltrating sensitive photos or other private data, and potentially even demanding a ransom.
  • According to Google Play Store, Android System SafetyCore has over 1 billion downloads and an average score of 3.6 stars from nearly 240,000 reviews.

Here’s the full article: https://cybernews.com/security/android-content-safety-manager-api-privacy-concerns/