BADBOX-Linked MoYu Hackers Abuse Android Car Head Unit Updates to Build Proxy Botnet
ID: e79f3e0a-af9d-5e41-8602-02d3fd29096d
STIX ID: report--e79f3e0a-af9d-5e41-8602-02d3fd29096d
Feed Name: Cyber Press
Security researchers uncovered the first documented malware campaign targeting Android-based automotive head units, attributed with high confidence to MoYu Group/BADBOX. The multi-stage operation abuses a legitimate TWCore firmware update pipeline to silently install a UI-less dropper (JarService), a loader that fingerprints devices and retrieves payloads, a clicker/reverse-proxy controller (BillingMain), and a 'zhima' module that enrolls head units into commercial proxy pools; the report includes IoCs, detection names, and notes vendor remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
