Kategorie
Hundreds of leaked AWS keys give full control over corporate accounts
ChatGPT wants Full Disk Access to your Mac and Messages
<br><!--<br>/* Style Definitions */<br> p.MsoNormal, li.MsoNormal, div.MsoNormal<br> {mso-style-unhide:no;<br> mso-style-qformat:yes;<br> mso-style-parent:"";<br> margin:0cm;<br> mso-pagination:widow-orphan;<br> font-size:12.0pt;<br> font-family:"Aptos",sans-serif;<br> mso-fareast-font-family:Aptos;<br> mso-bidi-font-family:"Times New Roman";<br> mso-fareast-language:EN-US;}<br>a:link, span.MsoHyperlink<br> {mso-style-priority:99;<br> color:#467886;<br> mso-themecolor:hyperlink;<br> text-decoration:underline;<br> text-underline:single;}<br>a:visited, span.MsoHyperlinkFollowed<br> {mso-style-noshow:yes;<br> mso-style-priority:99;<br> color:#96607D;<br> mso-themecolor:followedhyperlink;<br> text-decoration:underline;<br> text-underline:single;}<br>.MsoChpDefault<br> {mso-style-type:export-only;<br> mso-default-props:yes;<br> font-size:10.0pt;<br> mso-ansi-font-size:10.0pt;<br> mso-bidi-font-size:10.0pt;<br> font-family:"Aptos",sans-serif;<br> mso-ascii-font-family:Aptos;<br> mso-fareast-font-family:Aptos;<br> mso-hansi-font-family:Aptos;<br> mso-font-kerning:0pt;<br> mso-ligatures:none;}<br>@page WordSection1<br> {size:595.3pt 841.9pt;<br> margin:72.0pt 72.0pt 72.0pt 72.0pt;<br> mso-header-margin:35.4pt;<br> mso-footer-margin:35.4pt;<br> mso-paper-source:0;}<br>div.WordSection1<br> {page:WordSection1;}<br> /* List Definitions */<br> @list l0<br> {mso-list-id:1984120649;<br> mso-list-type:hybrid;<br> mso-list-template-ids:226894856 134807553 134807555 134807557 134807553 134807555 134807557 134807553 134807555 134807557;}<br>@list l0:level1<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Symbol;}<br>@list l0:level2<br> {mso-level-number-format:bullet;<br> mso-level-text:o;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:"Courier New";}<br>@list l0:level3<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Wingdings;}<br>@list l0:level4<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Symbol;}<br>@list l0:level5<br> {mso-level-number-format:bullet;<br> mso-level-text:o;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:"Courier New";}<br>@list l0:level6<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Wingdings;}<br>@list l0:level7<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Symbol;}<br>@list l0:level8<br> {mso-level-number-format:bullet;<br> mso-level-text:o;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:"Courier New";}<br>@list l0:level9<br> {mso-level-number-format:bullet;<br> mso-level-text:;<br> mso-level-tab-stop:none;<br> mso-level-number-position:left;<br> text-indent:-18.0pt;<br> font-family:Wingdings;}<br><br>--><br>Apple wasn’t joking when it <a style="color: rgb(150, 96, 125);" href="https://www.apple.com/newsroom/2025/09/the-digital-markets-acts-impacts-on-eu-users/">warned</a> us that competitors want access to our most private data. Now <a style="color: rgb(150, 96, 125);" href="https://www.computerworld.com/article/4212037/apple-to-openai-go-to-your-room.html">OpenAI’s ChatGPT</a>has introduced a new plugin that can control Apple’s Messages app on Macs. This follows its introduction earlier of a new Computer History feature that <a style="color: rgb(150, 96, 125);" href="https://x.com/OpenAI/status/2087996496088297746?s=20">monitors what you do on your Mac</a>, and while I don’t think Apple will challenge the new feature – yet – on Mac, I do see trouble ahead on other platforms.So, what’s ChatGPT’s new thing? Its latest tool means you can use the Chat GPT app to read, write and send texts via Messages. The app can also search through messages and get message summaries and other information directly from the Messages app. <b>What is happening?</b>“The Apple Messages plugin is available on all plans in the ChatGPT desktop app for macOS. In Codex and ChatGPT Work, it can read and search iMessage, SMS, and RCS chats on your Mac and send messages on your behalf through the Messages app. It doesn’t let you interact with ChatGPT remotely through Messages, and it doesn’t work in regular ChatGPT chats,” <a style="color: rgb(150, 96, 125);" href="https://learn.chatgpt.com/docs/plugins?surface=app">says OpenAI</a>.What this means is that if you’ve ever wanted an AI system to go through all your messages to give you insights, you’re in luck – though you’ll probably want to check in with corporate legal before doing so. The system does require user consent before working, and OpenAI itself suggests such permission is given only on a per-use, rather than a blanket basis.<b>How might you use this tool?</b>ChatGPT’s tool is not dissimilar to the contextual personal data insights promised by Apple’s SiriAI. You might use it to search for information buried in old messages, create new messages, delete them and more. You might get ChatGPT to recommend a set of secure browser and messaging services you can use to communicate without sharing your information with an AI company and ask it to write a cheery message about dystopia for you, for example. There’s an ad featuring much more mundane examples available <a style="color: rgb(150, 96, 125);" href="https://x.com/ChatGPT/status/2090499359641329950?s=20">here</a>.The company has suggested some prompts, including:<li class="MsoNormal">Suggest follow ups from yesterday in messages.Check my calendar and reply to (contact name) with a few times I'm free for dinner next week.Find birthdays in Messages and add them to my calendar.</li><b>How does it work?</b>The way the system works isn’t quite as clear as I’d like it to be, given the personal data being parsed by the system, along <a style="color: rgb(150, 96, 125);" href="https://tech.yahoo.com/general/articles/chatgpt-macos-just-got-caught-134547811.html">with recent history</a> on how ChtGPT protects such data on Macs. OpenAI told <a style="color: rgb(150, 96, 125);" href="https://www.bloomberg.com/news/articles/2026-08-20/chatgpt-can-now-control-imessage-potentially-raising-apple-privacy-concerns">Bloomberg</a> the plug-in runs locally on the Mac, and doesn’t create an index of a user’s messages, but that may not mean too much given the system does read a user’s existing messages and presumably has some kind of record of the data analysis itself. It is also not especially reassuring that OpenAI tells people not to turn on persistent approval, saying that doing so, “removes your final chance to review a message before ChatGPT sends it as you.”Perhaps of more concern is that the plugin also demands Full Disk Access in System Settings, along with access to contact names and automation tools. The plugin also makes use of AppleScript and Accessibility settings.<b>Something to think about</b>The degree to which OpenAI is digging into the macOS to make these features work is already driving some backlash. Some <a style="color: rgb(150, 96, 125);" href="https://x.com/markgurman/status/2090580272433832177?s=20">apologists</a> tend to dismiss concerns around privacy, while others warn that AI automation is becoming an <a style="color: rgb(150, 96, 125);" href="https://x.com/GaryMarcus/status/2090583038338236533?s=20">always-on surveillance system</a> that itself becomes a target for exploitation and attack. It’s possible both parties have a point, but what I don’t see yet is any clear transparency around how the system delivers all its promised convenience without undermining user privacy.It also seems very likely OpenAI plans to bring similar features to iPhones and iPads, which may yet open up a new front in Apple/OpenAI’s ongoing litigation around the provision of equal access to user data, particularly in Europe where <a style="color: rgb(150, 96, 125);" href="https://digital-markets-act.ec.europa.eu/developer-portal/interoperability_en">the Digital Markets Act</a> requires Apple to provide third-party AI developers with the same deep system-level APIs and device access that Apple uses for its own AI tools. It remains to be seen how Apple intends to meet that commitment, particularly as it has chosen not to offer SiriAI in Europe until it can agree some way to offer that kind of access to third parties while continuing to protect user privacy. It is also hard to ignore that ChatGPT on a Mac has now become a prime target for hackers, as if they can’t get into Messages directly, now all they need to do is hack the ChatGPT app to do it for them, perhaps using ChatGPT to <a style="color: rgb(150, 96, 125);" href="https://x.com/ControlAI/status/2090565786205118516?s=20">help them build the code with which to do it</a>. <b>What next? </b>I don’t think Apple will challenge OpenAI’s approach right now as the company doesn’t appear to have actively subverted Mac security protection, but I do predict a show down on iOS, particularly if Apple is unable to build support for the ‘<a style="color: rgb(150, 96, 125);" href="https://www.applemust.com/apples-siri-ai-stand-off-with-europe-just-escalated/">trusted intermediary’</a> approach it <a style="color: rgb(150, 96, 125);" href="https://www.applemust.com/eu-regulators-just-killed-europes-ios-developer-industry/">originally proposed</a> to the EU, if only because of the much wider extent of information collected on mobile. It also puts yet another slant on the <a style="color: rgb(150, 96, 125);" href="https://www.computerworld.com/article/4212037/apple-to-openai-go-to-your-room.html">ongoing litigation between both companies</a>.<em><span style="font-size: 13.5pt; font-family: Arial, sans-serif; color: rgb(12, 12, 12); letter-spacing: -0.15pt;">Join me on <a style="color: rgb(150, 96, 125); -webkit-font-smoothing: antialiased;" href="https://bsky.app/profile/jonnyevanssays.bsky.social"><span style="color: rgb(12, 12, 12);">BlueSky</span></a>, <a style="color: rgb(150, 96, 125); -webkit-font-smoothing: antialiased;" href="http://www.linkedin.com/in/jonnyevans"><span style="color: rgb(12, 12, 12);">LinkedIn</span></a>, <a style="color: rgb(150, 96, 125); -webkit-font-smoothing: antialiased;" href="https://social.vivaldi.net/@jonnyevans"><span style="color: rgb(12, 12, 12);">Mastodon</span></a> and <a style="color: rgb(150, 96, 125); -webkit-font-smoothing: antialiased;" href="https://thecorenews.substack.com/?r=5l3lg&utm_campaign=profile&utm_medium=profile-page"><span style="color: rgb(12, 12, 12);">subscribe to my newsletter</span></a> for news and analysis.</span></em>Apple wasn’t joking when it warned us that competitors want access to our most private data. Now, OpenAI’s ChatGPT has introduced a new plugin that can control Apple’s Messages app on Macs. This follows the earlier introduction of a new Computer History feature that monitors what you do on your Mac. And while I don’t think Apple will challenge the new feature — yet — on the Mac, I do see trouble ahead on other platforms.
So, what’s ChatGPT’s new thing? Its latest tool means you can use the tool to read, write and send texts via Messages. The app can also search through messages and get message summaries and other information directly from Messages.
What is happening?“The Apple Messages plugin is available on all plans in the ChatGPT desktop app for macOS,” says OpenAI. “In Codex and ChatGPT Work, it can read and search iMessage, SMS, and RCS chats on your Mac and send messages on your behalf through the Messages app. It doesn’t let you interact with ChatGPT remotely through Messages, and it doesn’t work in regular ChatGPT chats.”
So, if you’ve ever wanted an AI system to go through all your messages to pluck out insights, you’re in luck (though you’ll probably want to check in with corporate legal before doing so). The system does require user consent before working, and OpenAI itself suggests such permission is given only on a per-use, rather than a blanket basis.
How might you use this tool?ChatGPT’s tool is not dissimilar to the contextual personal data insights promised by Apple’s SiriAI. You might use it to search for information buried in old messages, create new messages, delete them, and more. You might get ChatGPT to recommend a set of secure browser and messaging services you could use without sharing your information with an AI company and ask it to write a cheery message about dystopia for you, for example. There’s an ad featuring much more mundane examples here.
The company has suggested some prompts, including:
- Suggest follow ups from yesterday in messages.
- Check my calendar and reply to (contact name) with a few times I’m free for dinner next week.
- Find birthdays in Messages and add them to my calendar.
The way the system works isn’t quite as clear as I’d like it to be, given the personal data being parsed, along with recent history on how ChatGPT protects such data on Macs.
OpenAI told Bloomberg the plug-in runs locally on the Mac, and doesn’t create an index of a user’s messages. But that may not mean much, given the system does read a user’s existing messages and presumably has some kind of record of the data analysis itself. It is also not especially reassuring that OpenAI tells people not to turn on persistent approval, saying that doing so, “removes your final chance to review a message before ChatGPT sends it as you.”
Perhaps of more concern is that the plugin also demands Full Disk Access in System Settings, along with access to contact names and automation tools.
Something to think aboutThe degree to which OpenAI is digging into the macOS to make these features work is already driving some backlash. Some apologists tend to dismiss concerns around privacy, while others warn that AI automation is becoming an always-on surveillance system that itself becomes a target for exploitation and attack. Both sides may have a point. But what I don’t see yet is any clear transparency around how the system delivers all its promised convenience without undermining user privacy. It’s all well and good to require consent to make the AI magic happen, but it would be far better, and more legitimate, for such consent to be informed.
It also seems very likely OpenAI plans to bring similar features to iPhones and iPads, which might yet open up a new front in Apple/OpenAI’s ongoing litigation around the provision of equal access to user data. That’s particularly true in Europe, where the Digital Markets Act requires Apple to provide third-party AI developers with the same deep system-level APIs and device access that Apple uses for its own AI tools.
It remains to be seen how Apple intends to meet that commitment, particularly as it has chosen not to offer SiriAI in Europe until it can agree on some way to offer that kind of access to third parties while continuing to protect user privacy. It is also hard to ignore that ChatGPT on a Mac has now become a prime target for hackers; if they can’t get into Messages directly, now all they need to do is hack the ChatGPT app to do it for them — perhaps using ChatGPT to help them build the code with which to do it.
What’s next?I don’t think Apple will challenge OpenAI’s approach for now, as the company doesn’t appear to have actively subverted Mac security protection. But I do predict a showdown on iOS, particularly if Apple is unable to build support for the “trusted intermediary” approach it originally proposed to the EU, if only because of the wider extent of information collected on mobile. It also puts yet another slant on the ongoing litigation between both companies.
Join me on BlueSky, LinkedIn, Mastodon and subscribe to my newsletter for news and analysis.
Microsoft blames Windows gaming issues on RGB lighting devices
Is Online Privacy Possible? How Digital Identities Can Help
Microsoft rolls out Classic Outlook theme for New Outlook users
Waymo doubles spending on lobbying in robotaxi battle with Uber
Waymo has sharply increased its lobbying spending as it seeks to persuade US regulators to clear a path for fully autonomous taxi services, intensifying its battle with rival Uber over the future of robotaxis.
The Alphabet-owned company spent more than $1 million between April and June on lobbying the federal government, more than double its outlay a year earlier, according to filings. That put Waymo’s spending close to Uber’s and well ahead of rivals including Amazon’s Zoox and Tesla.
The rise in lobbying comes as Waymo and Uber push competing visions for the future of ride-hailing. Waymo wants a faster route to fully driverless commercial services, while Uber is advocating a staggered rollout in which robotaxis operate alongside human drivers.
CISA orders feds to patch actively exploited TrueConf Server flaws
New ‘Slack Code’ turns AI coding into a team activity
With the launch of “Slack Code” channels, Slack this week introduced a new way for developers and non-tech staff to work collaboratively with coding agents.
While Slack already integrates with several coding agents, developers have to interact with them independently to get work done. The aim of Slack Code is to make agents available to multiple coworkers in shared, project-based “code channels.”
“We built code channels to be this multi-player AI experience and bring more development into Slack,” said Sateja Parulekar, vice president of product marketing at Slack. “It’s not just engineers and product managers who are working with the coding agents; it’s the marketers, the product designers who are now able to interact with a coding agent in a safe, governed environment.”
Slack code channels are intended for one-off coding sessions and projects — building a new application feature, updating a web page, or fixing a bug, for example.
When the coding agent is tagged in a Slack channel or DM with a request, it automatically creates a new code channel, adds links to required documents, and invites relevant participants.
The code channel functions just like a normal Slack channel, with participants able to send messages and files as usual, while also letting them interact with a coding agent and track outputs via the channel’s “session artifacts.” These artifacts include “code diffs” that highlight changes to code made by the agent, as well as Slack “canvas” documents and live HTML that displays prototypes and previews created by the agent.
All participants can use natural language to direct the agent, making suggestions and signing-off on outputs, for instance. Any updates are then highlighted in the original Slack channel. And when a task or project is complete, the code channel is automatically archived.
Slack Code channels can also be customized — Slack admins can create guardrails to prevent non-technical workers from shipping code without engineering review, for example.
Code channels adhere to Slack’s existing security and permissions model, the company said, with agents able to access conversations and data based on controls set for a Slack workspace.
At launch, four agents integrate with Slack Code — Claude Code, Devin, GitHub Copilot, and Vercel — though Slack intends to expand the list of options over time. Slack Code is available at no extra cost on all Slack subscriptions.
“Slack Code closes the gap between where work gets done and where code gets written with dedicated spaces built for output along project-based channels right in Slack,” said Wayne Kurtzman, research vice president at IDC. “This furthers the Salesforce goal of making work more seamless and multi-player within the Slack environment, regardless of the other applications the business is using.
“While Slack Code may seem early to market for some companies, others are leveraging the first-mover advantage.”
While software development and coordination work “has happened in Slack forever,” according to Will McKeon-White, senior analyst at Forrester, the new features make it “easier to just stay in Slack only and [open] up who is involved with the actual code creation.”
For IT staffers who enable Slack Code, the immediate consideration involves permissions, he said — “a persistent challenge for anything multiplayer.” McKeon-White cites various approaches: “…Some inherit user permissions based on task, some have persistent permissions with different ‘invoking’ permissions for users, some inherit the permissions of the room. Each has flaws.”
The longer-term challenge, he said, is around multi-agent collaboration.
“Multi-agent collab today in successful environments isn’t very dynamic,” said McKeon-White. “Having true dynamic agents cooperating can create extremely interesting emergent behavior,” he said, pointing to recent Anthropic research on the topic.
While Slack Code is aimed at software development-related tasks, Slack also envisages a similar cross-functional, collaborative approach to AI agent interactions applied to a wider variety of purposes: marketing campaigns, for instance, or legal document reviews.
“That might not involve code per se, but it does involve a very detailed review of a document and tracking changes and a preview of what’s going to be sent out to the customer,” said Parulekar. “In the future, we see this extending to a lot of different teams and use cases for technical and non-technical users.”
Other features announced Thursday include “agent DMs” that allow for individual interactions with an agent and a new “agents tab” where users can view existing agent conversations.
Parulekar said Slack Code feeds into a wider Slack strategy centered on a “multi-player experience” for human workers and AI agents. This includes the recent announcement of Claude Tag, which makes Anthropic’s agent available to teams.
“Whether it’s the user experience that we’re evolving — like the agent tab, or coding channels where you can plan, code, test, and ship inside of Slack — it’s all part of that bigger vision of making Slack a great home for agents and furthering that vision of multiplayer AI,” she said.
Wazuh and AI For Enhanced SOC Workflows
Microsoft warns of max severity Entra ID flaw exploited in attacks
Hackers abuse FTP server banners to deliver new Windows malware
SickKids data breach exposes employee and job applicant info
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
OpenAI adds an AI safety layer to detect misuse without retaining enterprise data
OpenAI is adding a new safety capability that allows enterprises to detect misuse of its AI systems across multiple interactions without retaining prompts or responses, enabling risk monitoring while preserving its Zero Data Retention (ZDR) commitments.
“OpenAI does not retain…prompts or model responses after a request is processed,” the company said in a blog post, describing its ZDR approach. The new system, called Private Safety Processing, is “designed to identify patterns across related interactions without giving OpenAI personnel access to the underlying content.”
The capability is being tested with eligible enterprise and API customers and is intended to address a limitation in existing safety controls that evaluate interactions individually, making it harder to detect risks that unfold over time.
What does Private Safety Processing doPrivate Safety Processing is designed to extend existing safety systems by correlating activity across related interactions rather than analyzing each prompt in isolation, according to OpenAI.
Under the model, automated systems analyze interactions and generate “a narrowly defined signal indicating the type of activity involved,” instead of exposing the underlying prompts or responses, according to OpenAI.
The system can operate whether customer data remains within enterprise-controlled infrastructure or is stored by OpenAI with encryption keys controlled by the customer, the company said.
“In both cases, automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel,” the post added.
Why existing safety controls fall shortOpenAI said the new capability is intended to address a gap in the detection of AI risks.
“The most serious AI safety risks are not always visible in a single interaction,” the company said, noting that harmful intent may only become clear when multiple interactions are viewed together.
Such risks include repeated attempts to probe safeguards, coordinated activity across accounts, and misuse that emerges over a sequence of interactions, according to the company.
As AI systems take on longer and more complex tasks, evaluating individual prompts in isolation can limit the ability to identify such patterns, OpenAI said in the post.
Diverging approaches to AI safetyThe introduction of Private Safety Processing highlights differing approaches to safety among AI providers.
OpenAI said the system is designed to detect misuse patterns across interactions while preserving zero data retention.
By contrast, some providers retain customer interaction data for a period of time to support safety monitoring, reflecting a different approach to identifying risks that span multiple requests.
Sanchit Vir Gogia, chief analyst at Greyhound Research, said the difference lies in how evidence is handled rather than whether signals are used.
“This is a disagreement about how much raw content you need besides a signal you are keeping regardless, rather than privacy against surveillance,” Gogia said.
He added that both approaches rely on derived indicators but differ in where investigation data resides. “Anthropic wants enough content to investigate the case. OpenAI wants the customer to hold the case while the provider holds the alarm,” he said.
Signal-based detection and verificationThe system’s reliance on signals rather than direct data access shifts how enterprises verify and investigate incidents, analysts noted.
“The architecture is entirely viable. Security has worked from derived indicators for a generation. The difficulty is verification, not feasibility,” Gogia said.
He added that detecting behavior across time requires retaining some form of representation. “A system cannot detect behaviour across time unless it remembers something across time,” he said.
Private Safety Processing “is privacy-preserving abuse detection. It is not an enterprise forensic record, and OpenAI does not claim it is,” he said.
Implications for regulated sectorsAccording to Apeksha Kaushik, senior principal analyst at Gartner, the approach could influence AI adoption in industries with strict data requirements.
“Privacy-preserving safety models, such as those employing Zero Data Retention (ZDR), represent an emerging approach that may lower barriers to AI adoption in regulated sectors like financial services and healthcare,” she said.
Such models “may help organizations address certain privacy requirements and may align with frameworks such as GDPR and HIPAA, contingent on specific implementation details and regulatory guidance,” she noted.
Kaushik added that organizations should evaluate such approaches against their compliance requirements. “Organizations are encouraged to consult with their compliance and legal teams to determine whether such approaches meet their specific regulatory and operational requirements,” she said.
OpenAI said enterprises retain control over their data under this model and can investigate alerts using their own systems. Customers can also choose to share relevant data with the company to support investigations or appeals.
Analysts say this shifts responsibility toward enterprises. “Zero Data Retention does not remove the forensic burden. It relocates it,” Gogia said.
The article originally appeared on CSO.
The invisible passenger in your car
While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. This led us to suspect the app might be reaching users’ devices without their knowledge. Further investigation confirmed that hypothesis and allowed us to reconstruct the entire infection chain.
Key findings:
- We identified new Android malware: a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet.
- The malware spread through the built-in updaters of Android-based automotive head unit firmware. This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.
- We attribute this activity, with high confidence, to the MoYu Group, an actor linked to the BADBOX botnet.
Kaspersky solutions detect the threats described below under the following detection names:
- HEUR:Trojan-Dropper.AndroidOS.Agent.vu
- HEUR:Trojan-Downloader.AndroidOS.Agent.ov
- HEUR:Trojan-Proxy.AndroidOS.Zhima.*
- HEUR:Trojan.AndroidOS.Vo1d.*
A head unit is a system that combines multimedia functions with partial control over certain vehicle functions. Head units may come as part of a car’s factory equipment or as an aftermarket upgrade. The main attack vectors for these systems are compromise via physical access and vulnerabilities in the head unit’s OS or components, both of which we’ve covered previously.
In some cases, head units run on Android, primarily because it’s convenient for manufacturers: Android’s source code already accounts for use cases within automotive head units. Android also allows manufacturers to add their own system applications during the build process, which they can use for a range of purposes: customizing the UI, adding system components tailored to the vendor’s needs, and more.
Most apps developed for Android devices can also run on an Android-based head unit, and that is true for malware as well. That said, it’s hard to imagine certain categories of smartphone-targeted malware being used to attack a head unit. Banking Trojans are a good example: since mobile banking is used almost exclusively on smartphones, infecting a head unit with a banking Trojan would be a waste of the attacker’s resources.
It’s worth noting that head units often include SIM card slots and can connect to the internet, enabling features like navigation and software updates. Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet – similar to attacks on IoT devices.
During our research, we found exactly that kind of malware. The design of firmware for DoFun head units enabled attackers to distribute malware. We notified the vendor about the distribution scheme, and they subsequently reported fixing the security issues.
Below is the entire infection chain:
Head unit infection scheme
Let’s look at exactly how these head units became infected.
The TWCore appTWCore is a legitimate system application responsible for collecting analytics data and updating the head unit software. Let’s take a closer look at how the update function works.
The process is fairly simple. An MQTT message broker hosted on the subdomain cardoor[.]cn sends a message containing information about the APK files that need to be downloaded and installed on the head unit. Notably, the object describing this message includes an installNotExists field, a Boolean flag that can be set to true or false. This flag allows TWCore to install apps that weren’t originally present on the device.
TWCore only checks whether an app is already installed on the device when installNotExists = false
The APK file is downloaded to <TWCore external cache dir>/push/apk/ for installation.
The path TWCore uses to download APK files
Our telemetry revealed previously unknown malware at these file paths. On top of that, our data indicates that in every observed case, the malware was installed by an app with the package name com.tw.core, which matches the TWCore package name.
Next, we’ll break down the malware installed by TWCore: the JarService dropper.
Stage 1: the JarService dropperAs mentioned earlier, JarService is a small dropper app with no UI of any kind. It decrypts data stored as encrypted blocks within the Trojan’s code. Each block is XOR-encrypted with a single-byte key that shifts linearly from block to block. The decrypted data contains serialized information about the payload version and entry point, along with the malware’s own code for further loading.
Decrypting and deserializing information about the stage 2 payload
In the version of JarService we analyzed, the entry point for the next-stage payload was the wa method of the com.c.j.qbh class.
Stage 2: the loaderThis stage’s payload is a malicious loader. Its code contains encrypted strings that are later used as class names to execute the stage 3 payload using the reflection mechanism. The loader sends implant information to one of the attackers’ servers via a POST request. Example of a request to the C2 server:
{ "userId": "REDACTED", "dexVersion": "1.7", "dexType": 1, "channelId": "2039", "packageName": "com.tw.jar1", "appVersion": 12, "appName": "JarService" }In response to the POST request, the C2 server returns a link for downloading the stage 3 payload. An example of a C2 response is shown below.
{ "code": 200, "data": { "dexUrl": "hxxp://144.217.243[.]201/vr34der34/dex3.68.png", "dexVersion": 3.680, "status": 0 } }The Trojan uses the link in the dexUrl field of the data object to download serialized data for loading the next stage. This data begins with a single-byte integer, a key used to decrypt the strings in the loader’s code. Immediately following this number is a four-byte floating-point value used to XOR-decrypt the stage 3 payload, which itself is located after these keys.
Decrypting the stage 3 payload
In the decrypted payload, the entry point is the init method of the com.ast.sdk.BillingMain class, shown in the screenshot below.
Entry point of the stage 3 payload
While analyzing this stage, we noticed that the download link for the next-stage payload includes a version number. We decided to try other version numbers to retrieve different payload versions, and ultimately obtained seven distinct variants, which we list under “Indicators of Compromise” at the end of this report. The earliest version, numbered 3.57, uses a different decoding algorithm than the one described above. This may indicate that an earlier version of the infection chain used a different loader between JarService and the stage 3 payload.
Stage 3: clicker / reverse proxy loaderIn this stage, the malware sends a POST request to /cpc/api/task every 90 minutes by default, containing information about the infected device (display resolution, device model, the SSID of the connected Wi-Fi network, MAC address, and so on) along with the Trojan’s configuration version. If the configuration is outdated, the C2 server returns an updated configuration containing new C2 addresses and new paths for sending HTTP requests. An example of a response is shown below. Note that at the time of our research, the most up-to-date configuration version was 3.82.
{ "code": 100, "data": { "configVersion": 3.820, "hosts": ["hxxp://t2.kshahnd[.]sbs", "hxxp://t2.mdsjhd[.]sbs", "hxxp://t2.nmnsny[.]sbs", "hxxps://t2.nmnsny[.]sbs"], "interval": 5500000, "reportApi": "/cpc/api/report", "tagName": "config", "taskApi": "/cpc/api/task", "updates": ["hxxp://a2.kshahnd[.]sbs", "hxxp://a2.mdsjhd[.]sbs", "hxxp://a2.nmnsny[.]sbs", "hxxps://a2.nmnsny[.]sbs"], "vn": 1.010 } }If the configuration version doesn’t need updating, the C2 server instead returns integer command identifiers, which the attackers refer to as productId. The Trojan maps each identifier to command information, which it stores as a serialized JSON object using the SharedPreferences API. Each identifier also has its own version, expressed as a UNIX timestamp. If the C2 response includes an unknown productId or one whose version is outdated, the malware sends a GET request to the attackers’ server at /cpc/api/xml to retrieve the command contents for all such identifiers. The C2 server responds with command information for each unknown identifier. An example of a response is shown below.
{ "code": 200, "data": [{ "productId": 979, "script": "{\n \"loadType\": 1,\n \"reload\": true,\n \"method\": \"start\",\n \"url2\": \"hxxp://144.217.243[.]201/vr34der34/sh65.io\",\n \"md52\": \"de77c3303e93c9450424759f1741441c\",\n \"name\": \"zhima\",\n \"className\": \"com.miyc.transfer.Client\",\n \"thread\": true,\n \"tagName\": \"loadlib2\",\n \"params\": [\n {\n \"type\": \"Context\"\n },\n {\n \"type\": \"String\",\n \"value\": \"107.151.248[.]132\"\n },\n {\n \"type\": \"String\",\n \"value\": \"1002\"\n },\n {\n \"type\": \"int\",\n \"value\": 1337\n },\n {\n \"type\": \"int\",\n \"value\": 7777\n },\n {\n \"type\": \"int\",\n \"value\": 8888\n },\n {\n \"type\": \"int\",\n \"value\": 15000\n }\n ],\n \"url\": \"hxxp://144.217.243[.]201/vr34der34/sh65.io\",\n \"md5\": \"de77c3303e93c9450424759f1741441c\"\n}", "version": 1778650942 }, { "productId": 1019, "script": "{\n \"loadType\": 1,\n \"reload\": true,\n \"method\": \"start\",\n \"url2\": \"hxxp://144.217.243[.]201/vr34der34/sh65.io\",\n \"md52\": \"de77c3303e93c9450424759f1741441c\",\n \"name\": \"zhima\",\n \"className\": \"com.miyc.transfer.Client\",\n \"thread\": true,\n \"tagName\": \"loadlib2\",\n \"params\": [\n {\n \"type\": \"Context\"\n },\n {\n \"type\": \"String\",\n \"value\": \"128.14.210[.]58\"\n },\n {\n \"type\": \"String\",\n \"value\": \"1002\"\n },\n {\n \"type\": \"int\",\n \"value\": 9999\n },\n {\n \"type\": \"int\",\n \"value\": 7777\n },\n {\n \"type\": \"int\",\n \"value\": 8888\n },\n {\n \"type\": \"int\",\n \"value\": 15000\n }\n ],\n \"url\": \"hxxp://144.217.243[.]201/vr34der34/sh65.io\",\n \"md5\": \"de77c3303e93c9450424759f1741441c\"\n}", "version": 1766001509 }, { "productId": 3505, "script": "{\n\"tagName\":\"http\",\n\"url\":\"hxxps://api.kookjar[.]com/sayhi?channel=daihai&uuid={get_uuid_10}\"\n}", "version": 1776656317 }], "msg": "" }The command information includes a tagName field, which is the command name. The code maps each name to the corresponding class responsible for executing it.
List of executable commands
At the time of our research, the attackers had implemented nine commands. The table below lists command names, brief descriptions, and arguments. The functionality of these commands suggests that the malware can be used to display ads, commit ad fraud (serving as a clicker), and download additional malicious code.
Command name Description Arguments return Return a value from SharedPreferences. key: the key whose value should be returned copy Set the contents of the clipboard. text: the key whose value from SharedPreferences is returned as the clipboard contentsurl: a link for downloading gzip-compressed data (optional); this data is then concatenated with the value of the text key, with (5 spaces) used as a separator http Make a POST/GET HTTP request to a specified resource and, if instructed, save the response in SharedPreferences under a specified key. url: the resource address
method: the HTTP method name (optional)
startLabel: a marker for the start of the data to save from the resource (optional)
endLabel: a marker for the end of the data to save from the resource (optional)
valueLabel: the key under which to save the value (optional)
header: a dictionary of headers for the HTTP request (optional)
content: the content of the POST request (optional) web Open a link in the WebView and execute arbitrary JavaScript code within it. url: the link to open in the WebView
js: base64-encoded JavaScript code to execute in the WebView; used when the url parameter is empty or absent
corejs: JavaScript code to execute when the resource loads in the WebView (optional)
param: a string dictionary of parameters for launching the WebView
client: if this key is present, WebViewClient is used to handle redirects manually
time: task timeout loadlib Not fully implemented at the time of publishing this report. – loadlib2 Download and execute arbitrary code. url: the address to download the payload from
name: the name of the module being downloaded
md5: the MD5 hash of the payload
clear: a comma-separated list of payload names to delete (optional)
params: an array of parameters to launch the payload with
className: the class name of the payload entry point
method: the name of the virtual method at the payload entry point
cmethod: the name of the static method used to instantiate the entry-point class (optional)
thread: a flag; the payload runs in a separate thread if this flag is not set
reload: a flag that, when set, restarts already loaded modules loadlib3 Not fully implemented at the time of publishing this report. – deeplink Open a resource in the browser. url: a link to the resource traceroute Check resource availability via an ICMP ping. host: comma-separated list of resources to check
However, attackers use only a relatively small subset of these commands in real-world attacks. As shown in the example C2 response above, at the time of publishing this report the attackers were using the loadlib2 and http commands. The payload downloaded via the loadlib2 command is a reverse proxy module named “zhima”, which researchers from the Nokia Deepfield Emergency Response Team independently discovered in TV set-top boxes around the same time as we did and also described in their report. This confirms that the attackers’ ultimate goal is building a proxy botnet.
While investigating this stage of the attack chain, we noticed that the zhima download link also included a version number. As with the previous stage, we tried other possible version numbers and found eight variants of the zhima module, the earliest of which was version 57. The complete list of identified zhima modules is provided under “Indicators of Compromise” below.
AttributionWhile analyzing the complete infection chain, we noticed that the stage 2 loader created a thread with the meaningful name mosdk-host-loader. We decided to investigate what mosdk referred to in that name. This led us to a malicious app installed on various TV set-top boxes with the package name com.abc.nexus (3AD4BF5A86D26FFBF09CAE42AF330A98). It consists of several components (including a dropper similar to JarService), each used by the attackers to covertly monetize the device’s computing power. Each malicious component in the app corresponds to its own service, and the service containing the launch code for the JarService-like dropper is named AdmoyuService. In light of this and the name of the malicious thread found in the payload code, we concluded that moyu in the service name referred to MoYu Group, one of the actors linked to the BADBOX malware platform, which had been described by researchers at HUMAN. This assessment is further supported by extensive overlap between the malware’s network infrastructure and that of MoYu Group, which was independently identified by researchers from the Nokia Deepfield Emergency Response Team around the same time as our own research. Based on these similar naming patterns and prominent infrastructure overlap between the activity of MoYu Group and the attacks described in this report, we attribute it to the same actor with high confidence.
While investigating the malware downloaded by TWCore, we noticed that the domain admin.uipoxy[.]com resolved to the IP address 128.14.210[.]58, one of the C2 servers for the zhima reverse proxy module. It appears that the URL hxxp://admin.uipoxy[.]com/proxy/u/login hosts the zhima admin panel. Interestingly, this panel allows anyone to register as long as they have a valid invite code.
The malware operator registration page
During registration, users are prompted to review the terms of use and privacy policy. Both documents are hosted on links under the pxyedge[.]com domain, which belongs to PXYEDGE, a vendor specializing in the sale of residential proxies.
On the registration page hosted at admin.uipoxy[.]com, we also found the string copyright © 2020 proxyforu[.]com all rights reserved, which linked to hxxps://proxyforu[.]com, the website of ProxyForU, another vendor of residential proxy services.
We found several similarities in the authentication APIs across all of these sites:
- The sign-in page was hosted on an admin.* subdomain.
- The sign-in page was located at /proxy/u/login.
- The signup page was located at /proxy/register?channelKey=<invitation code>.
Based on this, we believe these services are connected to MoYu Group.
ConclusionDespite efforts by cybersecurity professionals and law enforcement to shut down the BADBOX botnet, individual actors linked to it continue their malicious activity, infecting devices worldwide. Delivery methods for this kind of malware vary widely, from downloads via pre-installed backdoors to infected builds of IPTV apps. The case examined here demonstrates an even more sophisticated delivery method: distribution through the legitimate update functionality of a system application. Attackers are also actively expanding into new platforms. This malware is the first known malicious app targeting head units, which means these platforms now require protection against malware as well.
Indicators of compromise Stage 1: JarServiceba27951b4ee1c341f4415d033369ecd3
d63bacd6d6709dd68a10ef9d374c7835
6c2e34b30da42085240ede53ab6107d4
8b5e513144a6138a966ea59e68bf9da2
e119845877089d6f4b0a70dc7388f316
e9f3a0dab6949ce2cddab9e0aa80ae1a
Stage 3: loader/clicker0fbaa7092204f4b1494e0b840b014774
1dcf031c40ce456b6a36a00b0acf3d11
44b6b213a6a3f299eaf88e078de95ecb
67dc78e544ebce16b85dc7c195dfbc58
9642ae619b3165d23c6349002d1abe24
b067d5b0dbecbd6498bcdfba45dba77e
f0e3f7eba2cde91e2dedb921bab47422
412e9243f2981bbea3894254d105b3b8
71ab5517f71866279d0d87d37f2ae320
89ef78f716a75964539f2db6520be362
a4223ce4288a230d1e6c3ff2c7639045
bd4d81cd27125ad3d9a114922d468499
c6bfb1643ac7474ed8a7b4f96a187fdb
de77c3303e93c9450424759f1741441c
f8cf8c23ff597700d471fb7767df8bac
xmsae[.]sbs
ishano456[.]sbs
xshaon123[.]sbs
kshahnd[.]sbs
mdsjhd[.]sbs
nmnsny[.]sbs
kookjar[.]com
ty54fgd435[.]my
ue886578433[.]online
ty4523[.]space
144.217.243[.]201
107.151.248[.]132
128.14.210[.]58
hxxp://ovcloudcontrol.cdn.cardoor[.]cn/upgrade/2026-06-08/bd80bd3c3d0e4bf6b5b4a825650d01f5.apk
hxxp://ovcloudcontrol.cdn.cardoor[.]cn/upgrade/2025-06-10/fe71af9ecf174de48d2b2ccc2c15fb04.apk
hxxp://ovcloudcontrol.cdn.cardoor[.]cn/upgrade/2024-11-07/fa831c3c23824b99871163387bcda7ad.apk
2a64c3efc11bf224aa54f24e876446c9
7a4d3ba2dacccfdda55859a5dfee2671
ea24487996eb70c1780922fb3063bcc5
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Ad Blockers for Linux Browsers in 2026: Privacy, Performance, and Security Considerations
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



