Kaspersky is pretty much banned in the US because of the fact that it’s a Russian company, and the US and Russia don’t have the best relationship. So it appears that due to that, anyone who runs Kaspersky might have this happen to them:
Starting Thursday, Russian cybersecurity company Kaspersky deleted its anti-malware software from customers’ computers across the United States and automatically replaced it with UltraAV’s antivirus solution.
This comes after Kaspersky decided to shut down its U.S. operations and lay off U.S.-based employees in response to the U.S. government adding Kaspersky to the Entity List, a catalog of “foreign individuals, companies, and organizations deemed a national security concern” in June.
And:
In early September, Kaspersky also emailed customers, assuring them they would continue receiving “reliable cybersecurity protection” from UltraAV (owned by Pango Group) after Kaspersky stopped selling software and updates for U.S. customers.
However, those emails failed to inform users that Kaspersky’s products would be abruptly deleted from their computers and replaced with UltraAV without warning.
If I woke up one morning and my anti virus software were just replaced randomly. I would be really freaked out by that. I can look at this both ways. On one hand, Kaspersky needed to do the right thing to make sure that their customers in the US are secure. But on the other hand, the way they did it doesn’t really sit right with me. So as a result, I really don’t know how to feel about this. But strangely, I’m not done yet:
To make things worse, while some users could uninstall UltraAV using the software’s uninstaller, those who tried removing it using uninstall apps saw it reinstalled after a reboot, causing further concerns about a potential malware infection.
Some also found UltraVPN installed, likely because they had a Kaspersky VPN subscription.
This doesn’t exactly inspire confidence. Neither does this:
Not much is known about UltraAV besides being part of Pango Group, which controls multiple VPN brands (e.g., Hotspot Shield, UltraVPN, and Betternet) and Comparitech (a VPN software review website).
This seems a bit suspect to me. Personally, if I were affected by this, I’d be removing this software as quickly as possible possible and replacing it with some other anti virus software that I could trust. Because to be honest, I am not sure that I can trust these guys.
Supply chain attack infects Android car systems with botnet malware
Posted in Commentary with tags Kaspersky on August 24, 2026 by itnerdKaspersky researchers uncovered a supply chain attack infecting Android-based car head units with malware designed for ad fraud and proxy botnet activity.
The malware was distributed through the built-in updater of TWCore, a legitimate system application installed on head units from Chinese automotive technology provider DoFun. Researchers said this is the first documented malware infection chain specifically designed to target automotive head units.
The attack uses a three-stage infection chain, beginning when the legitimate updater downloads a malicious APK. Once installed, additional malware components are retrieved that can generate fraudulent advertising activity and turn the vehicle’s internet connection into a proxy for other traffic.
The threat is imminent. Today’s notice of the critical Keycloak Password Reset Flaw (CVE-2026-18963, CVSS 9.1) exposes thousands of enterprise identity servers to risk of complete, unauthenticated takeover.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“MoYu Group, the same actor behind BADBOX infections on cheap Android TV set-top boxes, expanded to car dashboards because to a residential proxy operator, any Android device with a Subscriber Identity Module (SIM) card is just inventory.
“DoFun’s TWCore updater accepts instructions from a Message Queuing Telemetry Transport (MQTT) broker and includes a flag called installNotExists that lets the server push entirely new applications to the device without human approval. The attackers pushed malware through this privileged deployment channel exactly as it was designed to work.
“The zhima proxy module on these head units ties back to residential proxy services PXYEDGE and ProxyForU, both connected to MoYu Group’s broader infrastructure. Compromised vehicles are being sold as proxy endpoints to whoever pays. A car sitting in a parking lot becomes someone else’s exit node, routing traffic through a cellular connection the vehicle owner pays for.
“Every original equipment manufacturer (OEM) sourcing Android-based head units from third-party firmware providers should be asking who audited the update channel before it shipped. Arbitrary code delivery already works through loadlib2, while loadlib and loadlib3 command paths were not fully implemented at the time of analysis. The proxy botnet is the current monetization model; the underlying access gives the operator considerably more capability than proxying traffic.”
John Strand, Owner, Black Hills Information Security, Inc.:
“If I’m looking at the overall trend of attacks we’ve been seeing lately, this fits right in. Supply chain attacks, malicious NPM packages, and similar techniques are increasingly showing up in some of the more advanced and interesting attacks. I’m not necessarily talking about ransomware here. I’m talking about attackers deliberately targeting areas that create blind spots for information security teams.
“For years, so much of information security has been focused on endpoints and EDR. More recently, organizations have started expanding that focus into cloud and identity security. That’s good, but attackers are moving into technologies that many traditional security stacks simply weren’t designed to monitor.
“Supply chain attacks are a perfect example. So is Android malware targeting head units used by automobile manufacturers. Most people aren’t running EDR on their car.
That sounds funny, but it highlights a serious problem.
“Attackers are finding technologies that fall outside the visibility of traditional security tools. Once they get into those environments, they have an opportunity to propagate, establish persistence, and potentially remain undetected for long periods of time. The problem isn’t necessarily that security teams aren’t paying attention. In many cases, the technology they’ve invested in simply doesn’t support these systems.”
Leave a comment »