
Hackers infect Android car head units to build proxy botnets
Security researchers at Kaspersky have uncovered a targeted supply-chain attack that infects generic Android-based car head units with malware. The operation hijacks the vehicle's infotainment system, turning the internet-connected dashboard screens into nodes for a proxy botnet and using them to commit advertising fraud. The attacks focus on hardware provided by DoFun, a Chinese company that supplies generic Android head units, software, and cloud services for vehicles. These systems typically act as the central command hub for a car's navigation, media playback, and general settings. Kaspersky researchers noted that this represents the first documented instance of an infection chain built specifically for car head units. The compromise stems from a legitimate system application called TWCore, which comes installed on the DoFun units. In June, investigators observed this application downloading a rogue APK file. The legitimate app receives its instructions through an MQTT server hosted on the cardoor[.]cn domain, which the attackers exploited to push the malicious payload. Once downloaded, the unknown application—identified as JarService—operates silently without any user interface. Upon launch, it immediately decrypts and executes a secondary loader program. This loader establishes a connection with a command-and-control server operated by the attackers and retrieves a final encrypted payload to install on the vehicle's system. The active malware periodically harvests and transmits specific details about the infected device back to its operators. This stolen data includes the hardware model, display resolution, Wi-Fi SSID, and MAC address. While connected to the command-and-control server, the infected head unit continually waits for further instructions. The primary function of the malware involves loading a reverse-proxy module called 'zhima'. This module forcibly enlists the car's hardware into a proxy botnet, allowing third parties to route their internet traffic through the vehicle's connection. The attackers also use the compromised units to generate automated web requests for click-fraud campaigns, monetizing the infection through fake advertising engagement. Despite hijacking the infotainment hardware, Kaspersky confirmed that the malware does not interface with or disrupt driving mechanics or critical vehicle control systems. The researchers attributed the campaign to MoYu, a threat actor group previously linked to the BadBox malware botnet operations. Following the discovery, Kaspersky reported the vulnerabilities and the active infection chain to DoFun. The Chinese manufacturer responded by stating that the issue has been resolved on their end. BleepingComputer has requested further clarification from both companies regarding how the original supply-chain compromise occurred. Generic Android head units are frequently installed as aftermarket upgrades in vehicles driven across Somalia and by the Somali diaspora. Motorists replacing factory radios with these inexpensive internet-connected screens should monitor device data consumption, as the background proxy and ad-fraud operations can quietly deplete hotspot or mobile data bundles.
Read our sourcing and corrections policy
This article was prepared by our automated editorial system, which summarized and translated the source above. No human editor reviewed this article individually before publication.



Be the first to comment on this story!