Hackers infect Android car head units with proxy botnet malware

Summary: A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]

Hackers Turn Android Car Head Units Into Residential Proxy Nodes

A supply-chain attack targeting Android-based car infotainment systems is quietly transforming infected vehicles into nodes of a criminal proxy network. Rather than interfering with steering, braking or other safety-critical functions, the malware exploits the car’s internet connection for residential proxy services and advertising fraud, effectively monetizing vehicles in the background without their owners realizing it.

Researchers at Kaspersky attributed the campaign to MoYu, a threat actor previously associated with the BadBox malware operation. The campaign targets Android head units from Chinese automotive technology provider DoFun and represents what researchers describe as the first documented malware infection chain specifically designed for this type of automotive device.

The attack begins with legitimate update software

The most significant aspect of the campaign is its distribution method. Researchers discovered that a legitimate DoFun system application called TWCore, responsible for receiving device instructions, was downloading a rogue APK onto affected head units. TWCore communicates through an MQTT server hosted atcardoor[.]cn, providing attackers with a route into devices that owners would normally consider trusted.

The downloaded malware, called JarService, deliberately has no visible interface. Once launched, it decrypts and executes a second-stage loader, which connects to command-and-control infrastructure and retrieves another encrypted payload. The final component periodically sends information about the infected device—including its model, screen resolution, Wi-Fi SSID and MAC address—and waits for commands from its operators.

The infection chain is particularly concerning because users do not need to install a suspicious application from an unofficial Android store. The malware arrives through software already present on the head unit, turning the device’s own update mechanism into the delivery channel.

The car becomes part of a proxy botnet

Kaspersky found that the attackers primarily deployed a reverse-proxy module named zhima. Once active, it allows external internet traffic to be routed through the compromised head unit, effectively converting the vehicle into a residential proxy endpoint. The attackers also generated web requests from infected systems as part of click-fraud operations.

This model has become increasingly attractive to cybercriminals because the compromised device’s IP address is often more valuable than its computing power. Traffic originating from an ordinary consumer internet connection may appear more legitimate to websites and anti-fraud systems than traffic coming from a known hosting provider or data center.

A compromised car connected through home Wi-Fi, a mobile hotspot or another consumer connection can therefore provide criminals with a legitimate-looking origin for automated traffic. Large numbers of infected devices can be aggregated into commercial proxy networks and rented to other actors for activities ranging from scraping and advertising fraud to attempts to circumvent geographic or anti-abuse restrictions.

The malware retains broader remote-control capabilities

Although proxy monetization appears to be the primary objective, JarService provides its operators with considerably more flexibility. The malware supports nine commands that allow attackers to retrieve stored values, manipulate the Android clipboard, issue HTTP GET and POST requests, open URLs inside WebView, execute supplied JavaScript and download additional executable modules. It can also launch browser resources and test connectivity to other hosts.

The ability to download and execute arbitrary modules is particularly important because it makes the malware extensible. The functionality observed by researchers today does not necessarily represent the complete set of capabilities attackers could deploy later.

For now, however, Kaspersky found no evidence that the malware interacts with driving or critical vehicle-control systems. The compromised hardware is the Android infotainment unit, and the observed operation is financially motivated rather than an attempt to manipulate the physical behavior of the vehicle.

Cars are becoming another category of IoT target

The campaign demonstrates how the expanding computing environment inside modern vehicles creates opportunities that resemble those already seen with routers, smart TVs and streaming boxes. Android-based head units are effectively embedded computers: they run applications, connect to networks, receive software updates and may remain deployed for many years.

Attackers do not necessarily need access to the vehicle’s most sensitive systems for compromising those devices to be profitable. An always-on Android computer with internet connectivity already provides useful resources.

That makes the incident less about “hackers taking control of cars” and more about the continuing expansion of the BadBox-style malware economy, where inexpensive consumer Android hardware can be quietly recruited into proxy and advertising-fraud networks.

The supply-chain element makes the problem harder for consumers to detect. Users can avoid installing suspicious applications and still become infected if the trusted software responsible for managing their device delivers the malicious payload itself.

DoFun says the problem has been resolved

Kaspersky notified DoFun about its findings, and the Chinese company told researchers that it had resolved the issue. The precise mechanism through which attackers initially compromised the distribution chain remains unclear, and BleepingComputer has requested additional information from the companies involved.

The incident nevertheless illustrates a broader automotive cybersecurity problem. As vehicles incorporate increasingly sophisticated Android systems and persistent internet connectivity, they inherit many of the same supply-chain risks that already affect smartphones, routers and other connected devices.

In this campaign, attackers were not interested in controlling how the car drives. They discovered something simpler and easier to monetize:every connected vehicle contains an internet connection and an IP address, and that alone can be valuable criminal infrastructure.

⁠Original report at BleepingComputer

Key facts

  • Hackers are infecting Android car head units with malware
  • The malware enlists compromised devices into a proxy botnet
  • The malware can also be used for ad fraud
  • The infection is spread through a legitimate device-update app
  • This represents a supply-chain attack targeting automotive infotainment systems

Why it matters

This attack highlights a significant vulnerability in the automotive software supply chain, demonstrating how compromised updates for consumer-facing devices like car head units can be leveraged for malicious purposes. The wide deployment of Android in vehicles means such attacks could impact a large number of users and potentially affect vehicle network security or user data, creating risks for manufacturers and consumers alike.