ZeroHour
The Recordpublished ()ingested

Hackers infecting Android car systems to build proxy botnet

mediumMalware exploited in the wildimportance 48
AI summary · glm-5.3-flash

Kaspersky reports MoYu Group-linked malware infecting DoFun Android car head units, enrolling them in a BadBox-linked proxy botnet for ad fraud and traffic routing.

Kaspersky discovered malware on Android-based head units made by Chinese automotive supplier DoFun, the first documented case of a car head unit being infected through an attack purpose-built for such devices. Attackers abused TWCore, a legitimate DoFun system application that handles updates and can install new apps, to silently push a malicious app called JarService that displays ads, generates fraudulent ad clicks and downloads additional malware. One malware module turns infected head units into reverse proxies so other users' internet traffic can be routed through the car's connection. Kaspersky attributes the campaign with high confidence to MoYu Group, linked to the BadBox operation, which previously infected over 70,000 Android devices and resurfaced as BadBox 2.0 after German authorities disrupted the original botnet in December 2024.

  • First documented malware infection of a car head unit via a purpose-built attack, per Kaspersky.
  • Attackers abused the legitimate TWCore updater to install JarService without any user interaction.
  • JarService runs without a UI, shows ads, commits ad-click fraud and downloads more malware.
  • A module converts infected head units into reverse proxies that route third-party internet traffic.
  • Kaspersky links the campaign to MoYu Group and the BadBox botnet, which resurfaced as BadBox 2.0 after Germany's 2024 takedown.
Full article537 words · extracted from therecord.media · click to collapse

A new malware is being used to infect Android-based car systems, turning the devices into part of a botnet, researchers warned in a report published Friday.

The malware was found on head units made by Chinese automotive software and hardware provider DoFun, Russian cybersecurity firm Kaspersky said. Head units are the computers and screens built into cars that control features such as navigation, music and Bluetooth.

Kaspersky said this is the first documented case of malware infecting a car head unit through an attack specifically designed for this type of device. Previous attacks against such systems have typically relied on physical access to a vehicle or vulnerabilities in their operating systems and other components.

"We notified the vendor about the distribution scheme, and they subsequently reported fixing the security issues," researchers added.

Kaspersky traced the infections to TWCore, a legitimate system application installed on DoFun devices that collects analytics and handles software updates. TWCore can also download and install new Android applications.

According to the report, attackers abused that functionality to push a malicious app called JarService onto affected devices without requiring drivers to click a link, visit a malicious website or install anything themselves.

JarService has no visible user interface and acts as a downloader for additional malicious code, making it difficult for drivers to notice that their devices have been compromised.

The malware can display advertisements and generate fraudulent ad clicks, but Kaspersky said its ultimate purpose appears to be expanding a botnet, networks of infected computers and other internet-connected devices that criminals can remotely use for cyberattacks, fraud and traffic routing.

One of the malware modules observed by researchers turns infected head units into reverse proxies. This allows other people's internet traffic to be routed through the infected device, making the activity appear to originate from the car's internet connection.

Kaspersky attributed the campaign with high confidence to MoYu Group, a threat actor linked to the BadBox malware operation, which has previously compromised Android smartphones, tablets, streaming devices and other internet-connected products.

“Despite efforts by cybersecurity professionals and law enforcement to shut down the BadBox botnet, individual actors linked to it continue their malicious activity, infecting devices worldwide,” Kaspersky researchers said.

BadBox has previously been linked to malware installed on Android devices before they reached consumers. In 2023, cybersecurity company HUMAN Security said it discovered more than 70,000 Android smartphones, connected TV boxes and tablets from at least one Chinese manufacturer that had been shipped with malware linked to the operation.

In December 2024, German authorities disrupted the original BadBox botnet by cutting off communications between infected devices and the hackers’ command-and-control infrastructure. However, the hackers quickly resurfaced with an updated version of the botnet.

The FBI also warned last year that BadBox 2.0 was targeting internet-of-things devices, including TV streaming boxes, digital projectors, digital picture frames and aftermarket vehicle infotainment systems.

No previous article

No new articles

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/android-botnet-china-hackers