BADBOX Malware Hijacks Aftermarket Car Screens to Build Global Botnet Network

www.news4hackers.com-badbox-malware-hijacks-aftermarket-car-screens-to-build-global-botnet-network-badbox-malware-hijacks-aftermarket-car-screens-to-build-global-botnet-network

Kaspersky has identified a malware campaign targeting Android-based automotive head units, leveraging update systems to enable ad fraud and residential proxy networks.

Exploitation of a Trusted Update Mechanism

The attack chain initiates through TWCore, a legitimate system application responsible for analytics collection and firmware updates on affected head units. Threat actors intercepted this trusted channel to distribute a malicious dropper named JarService, which installs without a user interface, ensuring stealth. This approach suggests the malware was engineered to remain undetected by vehicle owners. Once deployed, JarService transmits device-specific data to a remote server controlled by attackers. The server then issues commands to the infected device, enabling a range of malicious activities. These include altering clipboard content, initiating unauthorized web requests, and deploying a reverse proxy module known as zhima. This component, previously linked to campaigns targeting low-cost Android TV boxes, transforms infected head units into nodes within a proxy network.

Impact and Technical Details

The malware establishes communication with its command-and-control server every 90 minutes, exchanging information such as display resolution, model details, and Wi-Fi identifiers. Depending on the server’s response, it can execute additional payloads, including traffic interception and data exfiltration. The integration of zhima allows attackers to route internet traffic through compromised vehicles, masking their true origin while the device’s owner remains unaware of the breach.

Link to the MoYu Group and BADBOX Ecosystem

Kaspersky has attributed the campaign to the MoYu Group, a threat actor associated with BADBOX, a large-scale ad fraud and proxy network. BADBOX has previously compromised uncertified Android devices, including streaming boxes and digital picture frames. The recent discovery expands the ecosystem to include automotive infotainment systems. Google initiated legal action in July 2025 against 25 unnamed entities in China over BADBOX-related activities. Despite this, the infrastructure has persisted, with researchers noting its ability to adapt and reemerge following disruptions.

Mitigation and Industry Implications

The affected DoFun-based head units received firmware updates following Kaspersky’s responsible disclosure. However, the broader vulnerability highlights gaps in security standards for Android-based infotainment systems. As these devices become more prevalent, their internet connectivity and reliance on third-party updates create new attack vectors. The case underscores the risks of low-cost, unbranded connected devices sourced through unofficial channels. Compromised hardware can serve malicious purposes undetected, posing threats beyond its intended functionality. For consumers, this serves as a cautionary reminder of the security risks inherent in budget automotive technology. The incident adds automotive head units to a growing list of everyday devices exploited for ad fraud and proxy networks. As manufacturers and suppliers integrate more connected systems, addressing these vulnerabilities will be critical to preventing further exploitation.



About Author

en_USEnglish