Skip to content

Kaspersky Documents Malware Delivered Through Car Head-Unit Firmware Updates

Attackers abused TWCore, a legitimate update-delivery app, to install a trojan, a clicker that inflates ad impressions, and a module that recruits the unit into a botnet.

AI-generated illustration of malware targeting a car head unit
Illustration: techshooked · Generated with AI.

Kaspersky has documented malware delivered to Android-based car head units through an automatic firmware-update service, an approach it labels the first known case of that delivery route, with the infected devices recruited into a residential proxy botnet.

The June discovery, detailed by Kaspersky, shows attackers abusing TWCore, a legitimate system app that delivers software updates from the developer's cloud, to install a Trojan dropper called JarService on head units running DoFun software; DoFun's website says it serves more than 30 million vehicle owners worldwide. The dropper carries an encrypted next-stage payload and launches a malicious downloader that contacts the attackers' command-and-control server and executes additional code.

A clicker follows, used to inflate ad impressions, and a module called zhima adds the infected head unit to a botnet. The clicker stays in contact with the command server and reports device details including model, screen resolution, MAC address, and the connected Wi-Fi network, and it can accept commands from HTTP requests to opening web pages. Kaspersky's investigation connects the botnet to residential proxy services including PXYEDGE and ProxyForU, and links the operation to the BADBOX malicious platform and its associated MoYu Group.

For drivers the impact is staged rather than existential: the head unit can slow or become less stable, and the device's internet connection degrades as traffic routes through it. Because the malware can receive commands and download further payloads, consequences depend on what the botnet operators install next. Kaspersky says its experts informed the developer, which addressed the discovered issues, and a full technical analysis is published on Securelist.

Share this story

Daniel Brandt

Daniel Brandt covers threats, malware, and vulnerability disclosure for techshooked, from active exploit campaigns to the patch cycles that follow. His standard is operational: name the affected versions, separate a proof of concept from in-the-wild exploitation, and tell readers which fix to apply first.