logo

Malware Hijacks Android Car Head Units

ID: 8856d338-8f49-59b9-80a6-b532b6b060c5

STIX ID: report--8856d338-8f49-59b9-80a6-b532b6b060c5

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-08-22

Date Updated: 2026-08-22

Author: Pierluigi Paganini

...
...

Kaspersky researchers uncovered the first documented malware campaign targeting Android-based car head units, which abused a legitimate updater (TWCore) to push a multi-stage dropper (JarService) and loader that fetches payloads including a reverse proxy module ('zhima') to add infected vehicles to the BADBOX proxy network; the activity is attributed to MoYu Group and demonstrates attackers leveraging firmware update channels to scale a proxy botnet using cars' Internet connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.