TECH
Hackers breach in-car Android systems in a new type of digital attack
Kaspersky has revealed a malware campaign that managed to infiltrate Android systems installed in the central control consoles of various car models. The investigation, conducted in June, identified a sophisticated scheme that exploited the update mechanism built into the console firmware, turning the vehicles into unexpected targets for malicious activity. According to the company, this is the first documented case of an attack specifically designed for this type of equipment, which combines multimedia functions with—in some instances—control over the vehicle itself.
Researchers discovered that the attack originated in a legitimate system component called TWCore, which is responsible for collecting analytics and managing software updates. This module received instructions from the manufacturer's server regarding which applications to install or update. Attackers exploited this channel to introduce a dropper named JarService, which initiated a multi-stage infection chain that was both stealthy and difficult to detect. The malware installed itself like a standard application but lacked a visible interface, running silently in the background.
Nine distinct commands were identified, allowing operators to display unwanted ads, commit ad fraud, and download additional modules. The software also gathered device information, such as the model, screen resolution, connected Wi-Fi network, and MAC address. Although these units rarely store sensitive personal data, many maintain constant internet access and even support SIM cards. This makes them attractive targets for those seeking to expand botnets or exploit home networks via illicit proxies.
Technical analysis led researchers to link this campaign to the MoYu group, which is associated with the BadBox botnet. This botnet comprises Android devices compromised at the factory—including TV boxes, smartphones, and tablets. Operators use these devices for ad fraud, data theft, and the creation of proxy networks. The company found similarities between the control panel used in this attack and proxy services such as PXYEDGE and ProxyForU, reinforcing the link to the BadBox ecosystem.

DoFun, the manufacturer of the affected units, was notified by Kaspersky and has confirmed that the issue has been fixed. However, researchers warn that this case demonstrates a worrying trend: hackers are exploiting increasingly diverse and sophisticated methods to distribute malware, ranging from pre-installed backdoors to compromised IPTV applications. They are now targeting automotive platforms, which had not previously been considered a priority target.
For Kaspersky, this incident serves as a warning that the digital systems in modern cars require robust, ongoing protection against emerging threats. "Despite efforts by cybersecurity experts and authorities to dismantle the BadBox botnet, individual actors associated with it continue to carry out malicious activities, infecting devices worldwide," notes Kaspersky security researcher Dmitry Kalinin.
Create a botnet...This is the first documented case of malware infecting a car head unit via an attack specifically designed for this type of device, according to a report by a Russian company published on Friday.
The malware was found on head units manufactured by DoFun, a Chinese automotive software and hardware supplier whose systems are widely used in China and other Asia-Pacific countries. Researchers attributed the campaign with high confidence to the MoYu Group, a threat actor linked to the BadBox malware operation, which has previously compromised Android smartphones, tablets, streaming devices, and other internet-connected products.
Infection and functionalities...Kaspersky traced the infections to TWCore, a legitimate system application installed on DoFun devices that collects analytics and manages software updates. Attackers abused this functionality to push a malicious app called JarService to affected devices without requiring drivers to click a link or install anything, the report detailed.
JarService has no visible user interface and acts as a downloader for additional malicious code, making it difficult for drivers to notice the compromise. The malware can display ads and generate fraudulent clicks, but its ultimate goal appears to be expanding a botnet. One observed module turns infected units into reverse proxies, allowing other people's internet traffic to be routed through the infected device.
BadBox context...BadBox has previously been linked to malware installed on Android devices before they reached consumers. In December 2024, German authorities disrupted the original BadBox botnet by cutting off communications between infected devices and the hackers' command-and-control infrastructure, but the criminals quickly resurfaced with an updated version. The FBI also warned last year that BadBox 2.0 was targeting IoT devices, including aftermarket vehicle infotainment systems.
mundophone
