Kaspersky says it has found the first documented malware campaign built specifically around Android car head units, using the very firmware-update mechanism meant to keep the devices secure to enroll them into a proxy botnet instead.
What happened
Researcher Dmitry Kalinin, writing on Kaspersky’s Securelist blog, traced a multi-stage dropper called JarService that abuses TWCore, the legitimate system app that handles software updates on DoFun-brand Android head units. Rather than tricking a driver into sideloading an app, the campaign rides the device’s own update channel: a first-stage dropper installs quietly, a second stage phones home over an MQTT message broker to fetch further payloads, and a third stage installs a clicker and reverse-proxy module that turns the head unit into a node attackers can route traffic through. Infected devices check in with command infrastructure roughly every 90 minutes, reporting model and network details. Kaspersky attributes the campaign, with high confidence, to MoYu Group, an actor already linked to the BadBox botnet ecosystem, based on shared naming conventions and overlapping infrastructure.
Why it matters
Head units are internet-connected, largely unmonitored by drivers and security teams alike, and increasingly shipped with SIM slots, making them an attractive, low-visibility platform for ad fraud and proxy infrastructure that criminal traffic can hide behind. Nokia’s Deepfield researchers independently found the same malware family on TV set-top boxes, confirming this is one proxy-botnet operation spanning device categories most security teams never inventory.
The original angle
The interesting part is not that a botnet exists, it is the infection vector: a device’s own trusted update path, rather than a malicious app store listing, was the delivery mechanism. That mirrors a pattern CyberTech has flagged in recent supply-chain reporting and in coverage of malware disguised as trusted installers: attackers increasingly target the channel a device already trusts, rather than beating app-store or endpoint defenses head-on. For fleet operators and consumers alike, the fix is not a better antivirus app, it is scrutiny of who controls the firmware-update pipeline for every connected device on the network, not just laptops and phones.
Source: Kaspersky Securelist