TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Quarkslab

Tearing down a car telematic unit (and finding an accident on Facebook)

Romain Marchand · 2026-04-08 · Read original ↗

ATT&CK techniques detected

2 predictions
T1552.001Credentials In Files
58%
"and identify potential security issues. this initial review quickly revealed several obvious sensitive elements, including : wi - fi credentials stored in cleartext c $ cat conf _ fix / network. conf... apssid = q * * * * * * * _ wifi apkey = 8 * * * * * * 1 user access available…"
T1552.001Credentials In Files
52%
"= 1 7 + 1 enregistrements lus 7 + 1 enregistrements ecrits 474742784 octets ( 475 mb, 453 mib ) copies, 0, 3833 s, 1, 2 gb / s from there, the ubireader tool allowed us to obtain the full filesystem for the modem, custapp, and system partitions : $ ubireader _ extract _ files - i…"

Summary

From hardware analysis to OSINT: how we retrieved information about a BYD car crash by analyzing the TCU embedded memory.