Android Car Head Units Infected with Proxy Botnet Malware via Built-In Software Updaters

Security researchers have uncovered a novel Android malware campaign infecting connected car head units through legitimate software update mechanisms, repurposing automotive infotainment systems into nodes for an ad-fraud and proxy botnet.

Kaspersky researchers identified the infection vector, marking the first documented instance of malware specifically targeting car head units with an infection chain tailored to automotive hardware. The compromised units utilize firmware supplied by DoFun, a Chinese vendor providing infotainment software for aftermarket connected car head units.

The attack vector exploits TWCore, a legitimate system application responsible for collecting device analytics and delivering software updates. TWCore relies on a message broker hosted on the domain cardoor[.]cn to retrieve application binaries. According to researchers, an installNotExists boolean flag within the instruction payload permits TWCore to download and execute software packages absent from the factory installation.

Researchers attribute the malicious operation with high confidence to the MoYu Group, a threat actor associated with the global BADBOX botnet originally identified by HUMAN Security in 2023. The multi-stage infection process begins with JarService, a barebones dropper that unpacks and hands execution over to a secondary loader.

The secondary payload pings a command-and-control server every 90 minutes to transmit device telemetry, including screen resolution, hardware model, connected Wi-Fi network name, and MAC address. Analysis of the variant structure revealed seven distinct payload iterations and nine hardcoded operational commands, including remote HTTP requests, automated JavaScript execution within hidden browser views, and module deployment.

Active exploitation primarily leveraged the loadlib2 command to download zhima, a reverse proxy module designed to convert victimized infotainment systems into traffic-routing relays. Independent analysis by Nokia’s Deepfield team discovered identical proxy modules deployed concurrently against TV set-top boxes, confirming the broader botnet infrastructure.

Following responsible disclosure by Kaspersky, DoFun addressed the vulnerability and closed the firmware update gap. Investigators emphasize that the incident highlights an urgent requirement for rigorous endpoint security protections across non-traditional Android endpoints, including connected vehicle computing units.

Leave a Reply

Your email address will not be published. Required fields are marked *