Hackers infect Android car head units with proxy botnet malware

A sophisticated supply-chain attack has compromised thousands of Android-based car head units, turning them into proxy botnets or using them for ad fraud. The malware, attributed to the notorious MoYu group, was spread through a legitimate device-update app and allows attackers to remotely control infected devices.

The target of the attack is DoFun, a Chinese automotive software and hardware provider that sells generic Android-based head units used as command centers in cars’ infotainment, navigation, and settings systems. Researchers at Kaspersky discovered a rogue APK file being downloaded from a legitimate DoFun system app, TWCore, which receives instructions through an MQTT server hosted on cardoor[.]cn. The malware, known as JarService, has no interface but communicates with a command-and-control (C2) server to download and execute additional payloads.

Infected devices periodically report device information such as the model, display resolution, Wi-Fi SSID, and MAC address, and retrieve commands from attackers. The malware supports nine commands, including retrieving values from Android’s SharedPreferences storage, sending HTTP requests, and opening URLs in a WebView. While Kaspersky notes that the malware does not interfere with driving or critical vehicle control systems, it appears designed for advertising fraud and turning internet-connected car head units into residential proxy nodes.

The MoYu group has been linked to the BadBox malware botnet, but this is the first documented case of a malware infection chain specifically created for targeted car head units. Kaspersky researchers discovered that the operator primarily loaded a reverse-proxy module named ‘zhima,’ which turns the head unit into a proxy botnet node, and also made web requests for click-fraud activity.

The Chinese company DoFun has acknowledged receiving notification from Kaspersky about the issue and claims to have resolved the problem. However, it is unclear how attackers initially compromised the system or whether other similar vulnerabilities exist. As more devices are connected to the internet, the risk of such supply-chain attacks grows, highlighting the need for robust security measures in automotive software and hardware.

The incident serves as a reminder that even seemingly innocuous apps can be exploited by attackers. Car owners should remain vigilant and ensure their vehicles’ head units are running with up-to-date security patches. Furthermore, manufacturers must prioritize the security of connected devices and regularly monitor for potential vulnerabilities to prevent similar attacks in the future.


Source: Bleeping Computer — 2026-08-22