HomeSecurityAndroid car head units: Malware hides in updates

Android car head units: Malware hides in updates

Android car head units, the infotainment screens that serve as the navigation and entertainment hubs in many cars, have been at the center of a new supply chain attack. A malicious application distributed through the built-in update mechanism can turn the device into a proxy node and ad fraud tool.

Android car head units malware

BleepingComputer 's analysis , based on findings from Kaspersky, links the campaign to the MoYu group, which has been associated with the BADBOX ecosystem. This is the first documented infection chain specifically designed for car infotainment units.

So far, there is no indication that the campaign affects factory systems from all manufacturers. The risk mainly concerns compatible third-party units and highlights the need to check the origin before any upgrade.

See also: Manic Android malware: Banking trojan and spyware

How Android car head units get infected

At the center are units based on software and hardware from China's DoFun, a company owned by Shenzhen Driving Control Technology. The Android car head units use the TWCore system application for analytics and updates, receiving instructions from an MQTT message broker on a subdomain of cardoor[.]cn.

Kaspersky researchers detected an unknown APK in June being downloaded from the legitimate TWCore and stored in the temporary updates folder before installation. The application does not display a normal user interface and uses the name JarService. Upon launch, it decrypts a second-stage loader, which connects to a control server and downloads the final payload.

Android car head unit infection

From update to proxy botnet and ad fraud

The final payload collects information such as the device model, screen resolution, Wi-Fi ID, and MAC address, while accepting commands from operators. According to The Hacker News, the malware supports nine commands to display unwanted ads, perform ad fraud, and download additional modules.

The most prominent module is zhima, a reverse proxy that turns each infected module into a network node. This allows third-party traffic to be routed through the car's connection and appear to be from the user's IP address. The same infrastructure is selectively exploited for fake ad clicks rather than for engine control or critical driving functions.

Kaspersky estimates that the activity is mainly aimed at generating revenue from ad fraud and home proxy services. For infotainment unit users, this means that the vehicle’s connection can be secretly used for extraneous traffic, without necessarily showing any immediate malfunction on the screen. No number of infected units or full geographical distribution has been published, and the research does not document that attackers gain access to the vehicle’s control systems. This distinction is important: the risk concerns privacy, connectivity, and resource abuse.

Proxy botnet on Android car head units

See also: Android banking trojans: ToxicPanda 2.0 and GoldDigger expand attacks

What owners and builders should do

DoFun was notified by Kaspersky and responded that it had addressed the issue. For owners, however, practical protection depends on how updates are distributed. Do not install APKs from unknown sources, check if the unit is receiving official firmware, and ask the vendor for confirmation of the TWCore version.

Manufacturers must cryptographically sign packages, restrict which servers can send commands, strictly control the permissions of the update application, and log each installation. This process is critical for these devices because the update is privileged and can be executed before the driver is aware of any changes. Simply using a legitimate update mechanism is not enough when the mechanism can accept an unauthorized APK or execute payload without any visible indication to the driver.

Android car head unit protection

At the network level, segmenting Android car head units from other devices in the vehicle and home network limits lateral traffic. Unusual data traffic, unexpected proxy connections, increased network usage, or repeated attempts to communicate with unknown servers are worth investigating. The SecNews technical team also recommends performing a factory reset only after ensuring that the next update is clean and official.

See also: StopAndProtect: 2,000 hacked WordPress sites for malware distribution

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The case shows that the security of Android car head units depends not only on the display or operating system, but also on the vendor's update chain. The more features are connected to the internet, the more important it is to verify the origin, signature and behavior of each packet before it reaches the device.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS