Android car head units infected with proxy botnet malware through built-in software updaters
ID: 1788fac9-5958-5b24-80ad-c414c5db7a24
STIX ID: report--1788fac9-5958-5b24-80ad-c414c5db7a24
Feed Name: Help Net Security
Threat Score
Kaspersky discovered an Android malware campaign that abuses the legitimate TWCore updater on DoFun-based car head units to install a three-stage payload (JarService dropper → loader → controller). The malware gathers device data, supports nine commands (notably http and loadlib2), and installs a reverse-proxy module (zhima) to build a proxy/ad-fraud botnet attributed to the MoYu Group (BADBOX ecosystem); DoFun has patched the flaw after disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
