Hackers infecting Android car systems to build proxy botnet
A new malware is being used to infect Android-based car systems, turning the devices into part of a botnet, researchers warned in a report published Friday.
The malware was found on head units made by Chinese automotive software and hardware provider DoFun, Russian cybersecurity firm Kaspersky said. Head units are the computers and screens built into cars that control features such as navigation, music and Bluetooth.
Kaspersky said this is the first documented case of malware infecting a car head unit through an attack specifically designed for this type of device. Previous attacks against such systems have typically relied on physical access to a vehicle or vulnerabilities in their operating systems and other components.
"We notified the vendor about the distribution scheme, and they subsequently reported fixing the security issues," researchers added.
Kaspersky traced the infections to TWCore, a legitimate system application installed on DoFun devices that collects analytics and handles software updates. TWCore can also download and install new Android applications.
According to the report, attackers abused that functionality to push a malicious app called JarService onto affected devices without requiring drivers to click a link, visit a malicious website or install anything themselves.
JarService has no visible user interface and acts as a downloader for additional malicious code, making it difficult for drivers to notice that their devices have been compromised.
The malware can display advertisements and generate fraudulent ad clicks, but Kaspersky said its ultimate purpose appears to be expanding a botnet, networks of infected computers and other internet-connected devices that criminals can remotely use for cyberattacks, fraud and traffic routing.
One of the malware modules observed by researchers turns infected head units into reverse proxies. This allows other people's internet traffic to be routed through the infected device, making the activity appear to originate from the car's internet connection.
Kaspersky attributed the campaign with high confidence to MoYu Group, a threat actor linked to the BadBox malware operation, which has previously compromised Android smartphones, tablets, streaming devices and other internet-connected products.
“Despite efforts by cybersecurity professionals and law enforcement to shut down the BadBox botnet, individual actors linked to it continue their malicious activity, infecting devices worldwide,” Kaspersky researchers said.
BadBox has previously been linked to malware installed on Android devices before they reached consumers. In 2023, cybersecurity company HUMAN Security said it discovered more than 70,000 Android smartphones, connected TV boxes and tablets from at least one Chinese manufacturer that had been shipped with malware linked to the operation.
In December 2024, German authorities disrupted the original BadBox botnet by cutting off communications between infected devices and the hackers’ command-and-control infrastructure. However, the hackers quickly resurfaced with an updated version of the botnet.
The FBI also warned last year that BadBox 2.0 was targeting internet-of-things devices, including TV streaming boxes, digital projectors, digital picture frames and aftermarket vehicle infotainment systems.
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.



