logo

BADBOX-Linked MoYu Hackers Abuse Android Car Head Unit Updates to Build Proxy Botnet

ID: e79f3e0a-af9d-5e41-8602-02d3fd29096d

STIX ID: report--e79f3e0a-af9d-5e41-8602-02d3fd29096d

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Kavichselvan

...
...

Security researchers uncovered the first documented malware campaign targeting Android-based automotive head units, attributed with high confidence to MoYu Group/BADBOX. The multi-stage operation abuses a legitimate TWCore firmware update pipeline to silently install a UI-less dropper (JarService), a loader that fingerprints devices and retrieves payloads, a clicker/reverse-proxy controller (BillingMain), and a 'zhima' module that enrolls head units into commercial proxy pools; the report includes IoCs, detection names, and notes vendor remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.