Hackers Exploit Android Car Head Units via Proxy Botnet Malware

www.news4hackers.com-hackers-exploit-android-car-head-units-via-proxy-botnet-malware-hackers-exploit-android-car-head-units-via-proxy-botnet-malware

Hackers infect Android car head units with proxy botnet malware

The Threat and Its Origins

Kaspersky researchers have identified a supply chain compromise targeting Android-based automotive head units, leveraging a legitimate device-update application to distribute malware that enlists affected devices into a proxy botnet or exploits them for ad fraud activities.

The MoYu Threat Group

The malicious campaign has been linked to the MoYu threat group, which previously operated the BadBox malware botnet. This marks the first known instance of a malware chain specifically designed for automotive head units.

The Target: DoFun Systems

The attack focuses on systems manufactured by DoFun, a Chinese provider of automotive software, cloud services, and hardware under Shenzhen Driving Control Technology Co., Ltd. DoFun supplies generic Android-based head units that serve as central control hubs for vehicle infotainment, navigation, and settings.

Malware Functionality and Attack Vector

In June, Kaspersky detected a rogue APK file distributed through compromised update channels. The malicious application, named JarService, lacks a user interface and functions as a backdoor. Upon execution, it decrypts and deploys a second-stage loader that establishes communication with a command-and-control (C2) server.

Key Commands and Capabilities

The final payload periodically transmits device metadata, including model details, display resolution, Wi-Fi SSID, and MAC address, while receiving instructions from attackers. The malware supports nine distinct commands: retrieving values from Android’s SharedPreferences storage, copying data to the device clipboard, executing HTTP GET/POST requests, opening URLs in a WebView with JavaScript execution, downloading and executing arbitrary code, and performing ICMP ping tests.

The Reverse-Proxy Module

Kaspersky notes that the malware does not interfere with driving or critical vehicle systems, suggesting its primary purpose is ad fraud and monetization through residential proxy networks. Researchers identified a reverse-proxy module called zhima, which transforms infected head units into proxy botnet nodes. The malware also facilitates click-fraud activities by generating web traffic.

Response and Broader Implications

Kaspersky reported the findings to DoFun, which confirmed the issue had been addressed. BleepingComputer is investigating the initial compromise vector and plans to update the report with additional details once responses are received.

Vulnerabilities in Automotive Software

The incident highlights vulnerabilities in automotive software ecosystems, as attackers exploited valid credentials to bypass security measures. According to The Blue Report 2026, 37% of malicious actions go undetected when adversaries possess legitimate access.

Related developments include the disruption of the NetNut proxy network, which severed connections from 2 million infected devices, and the emergence of new Android malware capable of data exfiltration via nearby devices. Other recent threats include the Evooo1Bot Linux botnet, which repurposes routers for traffic relaying, and the Android BTMOB RAT malware.

Conclusion

The attack underscores the growing risk of compromised automotive software, with implications for both consumer privacy and enterprise security. As vehicle systems become increasingly connected, securing supply chains and update mechanisms remains critical to preventing similar incidents.



About Author

en_USEnglish