Head unit infection scheme | Image: Kaspersky Labs
At a glance
| Factor | Details |
|---|---|
| Malware Family | JarService dropper and zhima proxy module |
| Threat Actor | MoYu Group (High confidence attribution; linked to BADBOX botnet) |
| Targets | Android-based automotive head units (DoFun firmware) |
| Delivery Vector | Built-in system updater (TWCore) via MQTT command broker |
| Key Capabilities | Silent app installation, ad click fraud, residential proxy routing |
| Source | Kaspersky Labs, Nokia Deepfield, and HUMAN Security |
Kaspersky researchers uncovered a campaign delivering Android head unit malware to smart vehicle infotainment systems. The operators hijack legitimate firmware update tools to install droppers without driver interaction. As a result, the compromised units secretly route residential proxy traffic and execute advertising fraud.
Delivery
The attack targets infotainment hardware running customized Android builds, specifically systems produced for DoFun vehicles. According to an investigation published by Kaspersky Labs, attackers compromise the device through its pre-installed maintenance software.
Specifically, the system relies on a legitimate telemetry application named TWCore to manage software updates. During normal operation, an MQTT message broker transmits package instructions to the vehicle. However, the update protocol contains a dangerous configuration flag named installNotExists. When attackers send instructions with this flag enabled, TWCore downloads and installs arbitrary application packages into internal storage. The system updater runs with elevated privileges, so it installs packages without displaying user prompts.
Infection Chain
The intrusion proceeds through four distinct operational stages to deploy the final botnet module. First, the updater drops a lightweight application named JarService onto the file system. JarService contains no graphical interface and conceals its code within XOR-encrypted data blocks.
Next, JarService decrypts an intermediary loader that initiates outbound communication with external servers. This loader transmits device parameters and fetches an encrypted third-stage archive. The malware then executes this downloaded payload using Java reflection.
Kaspersky emphasized the historical novelty of this threat in their advisory. Researchers stated, “This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.”
In the third stage, the payload establishes periodic contact with remote task servers. The malware checks for new commands every ninety minutes. It supports several operational instructions, including clipboard modification, background browser execution, and auxiliary module downloads. Finally, the third stage fetches a modular payload called zhima, which operates a full SOCKS5 and HTTP reverse proxy.
Command-and-Control and Attribution
The command infrastructure connects directly to known residential proxy monetization networks. Kaspersky identified administrative portals operating on external servers associated with proxy vendors ProxyForU and PXYEDGE. These portals sell access to residential network traffic generated by infected consumer electronics.
Furthermore, researchers established clear links to previously documented cybercrime operations. Analysts noted, “We attribute this activity, with high confidence, to the MoYu Group, an actor linked to the BADBOX botnet.”
Independent telemetry from the Nokia Deepfield Emergency Response Team and research from HUMAN Security confirmed these findings. Both teams observed substantial network and code overlaps between the zhima proxy module and older botnet strains found on consumer television set-top boxes.
Defense and Detection Guidance
Defending automotive platforms requires strict controls over device firmware and network traffic. Following responsible disclosure, the affected vendor reported deploying firmware updates to fix the updater flaw.
Vehicle owners should ensure their automotive entertainment systems run the latest manufacturer updates. In addition, fleet managers should monitor connected vehicle data usage for unusual outbound HTTP or SOCKS5 connections. Restricting unsolicited background installations and disabling unauthenticated remote MQTT channels prevents similar Android head unit malware infections across smart transportation networks.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.