logo

Android car head units infected with proxy botnet malware through built-in software updaters

ID: 1788fac9-5958-5b24-80ad-c414c5db7a24

STIX ID: report--1788fac9-5958-5b24-80ad-c414c5db7a24

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Sinisa Markovic

...
...

Kaspersky discovered an Android malware campaign that abuses the legitimate TWCore updater on DoFun-based car head units to install a three-stage payload (JarService dropper → loader → controller). The malware gathers device data, supports nine commands (notably http and loadlib2), and installs a reverse-proxy module (zhima) to build a proxy/ad-fraud botnet attributed to the MoYu Group (BADBOX ecosystem); DoFun has patched the flaw after disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.