Researchers have uncovered car head unit malware that infects Android-based infotainment systems through a legitimate device-update app. The campaign appears designed to turn compromised systems into proxy botnet nodes and support advertising fraud.

Kaspersky attributed the activity to the MoYu group, which researchers have previously linked to the BadBox malware botnet. The company described it as the first documented infection chain created specifically for targeted Android car head units.

Legitimate update app delivered the malware

The campaign targeted head units made by DoFun, a Chinese provider of automotive hardware, software and cloud services. These generic Android devices can manage infotainment, navigation and vehicle settings.

In June, researchers discovered a rogue APK download originating from TWCore, a legitimate DoFun system app. TWCore reportedly received instructions through an MQTT server.

The downloaded app had no visible interface. Researchers named the malware JarService.

When it launches, JarService decrypts and runs a second-stage loader. That loader contacts a command-and-control server and downloads another encrypted payload.

Malware collects device data and waits for commands

The final payload regularly sends device information to the attackers. The collected details can include the device model, screen resolution, Wi-Fi network name and MAC address.

It can also receive commands from the attackers. Those commands allow the malware to read stored data, copy content to the clipboard, send web requests and open browser resources.

One command can download and execute extra code or modules. This gives the attackers flexibility to change the activity on infected systems after the initial compromise.

Proxy module turns head units into botnet nodes

Researchers said the operators mainly used a reverse-proxy module called zhima. It turns an internet-connected car head unit into a node in a proxy botnet.

Criminals can use these proxy nodes to route traffic through other people’s devices. This can help them hide the origin of malicious activity or sell access to residential-style internet connections.

The malware also made web requests associated with click fraud. That activity can generate false advertising engagement and create revenue for the operators.

Malware does not target vehicle controls

Kaspersky said the car head unit malware does not interfere with driving or critical vehicle-control systems. The campaign appears focused on monetising the head units’ internet connections rather than affecting vehicle safety.

That distinction is important, but the infection still creates privacy and security risks. Attackers could collect data from the device, misuse its network connection and install further modules.

Kaspersky said it notified DoFun about the findings. According to the researchers, the company responded that it had resolved the issue.

Owners of Android-based head units should install updates only through trusted sources and remain cautious of unexpected downloads or software changes.


0 responses to “Car Head Unit Malware Builds Proxy Botnet From Android Devices”