Android Car Systems Targeted by New Malware, Forming Automotive Botnet
A novel malware campaign is infecting Android-based car head units, transforming these in-vehicle systems into components of a malicious botnet. This marks the first documented instance of malware specifically designed to compromise automotive head units through their inherent update mechanisms, bypassing traditional attack vectors.
# Android Car Systems Compromised in Novel Botnet Attack
**Kaspersky** researchers have uncovered a new malware strain actively infecting **Android**-based car head units, leveraging these devices to expand a sophisticated botnet. The attack, attributed to the **MoYu Group**, highlights a concerning evolution in cyber threat landscapes, moving beyond conventional endpoints to target in-vehicle infotainment systems.
## The Infection Vector: Abusing Legitimate Software
The malware was discovered on head units manufactured by **DoFun**, a Chinese provider of automotive software and hardware. Unlike previous attacks that relied on physical access or operating system vulnerabilities, this campaign exploits a legitimate system application called **TWCore**.
**TWCore**, pre-installed on **DoFun** devices, is designed for analytics collection and software updates, crucially possessing the capability to download and install new **Android** applications. Threat actors abused this functionality to push a malicious app, **JarService**, onto devices without requiring user interaction, such as clicking links or manual installations.
## JarService: Covert Operations and Botnet Expansion
**JarService** operates with no visible user interface, acting primarily as a downloader for additional malicious code. This stealthy operation makes it exceedingly difficult for drivers to detect the compromise of their car systems.
While **JarService** can display advertisements and generate fraudulent ad clicks, **Kaspersky** suggests its primary objective is botnet expansion. Infected head units are transformed into reverse proxies, allowing threat actors to route other internet traffic through the compromised vehicle's connection, obscuring the origin of malicious activities.
## Attribution to MoYu Group and BadBox Legacy
**Kaspersky** has attributed this campaign with high confidence to the **MoYu Group**, a threat actor previously linked to the notorious **BadBox** malware operation. The **BadBox** botnet has historically compromised a wide array of **Android** devices, including smartphones, tablets, and streaming devices.
Despite efforts by cybersecurity professionals and law enforcement to dismantle the original **BadBox** botnet β including a disruption by German authorities in December 2024 β actors linked to the operation continue to evolve. The **FBI** also issued warnings last year about **BadBox 2.0** targeting **IoT** devices, specifically mentioning aftermarket vehicle infotainment systems.
## Implications for Automotive Cybersecurity
This incident underscores a critical vulnerability in the expanding ecosystem of connected vehicles. As cars become increasingly integrated with digital technologies, securing their embedded systems against sophisticated cyber threats becomes paramount. The exploitation of legitimate update mechanisms represents a significant challenge, requiring robust supply chain security and continuous monitoring for suspicious activity. **Kaspersky** confirmed that they notified **DoFun** of the distribution scheme, and the vendor subsequently reported fixing the security issues.
