Kaspersky has documented malware delivered to Android-based car head units through an automatic firmware-update service, an approach it labels the first known case of that delivery route, with the infected devices recruited into a residential proxy botnet.
The June discovery, detailed by Kaspersky, shows attackers abusing TWCore, a legitimate system app that delivers software updates from the developer's cloud, to install a Trojan dropper called JarService on head units running DoFun software; DoFun's website says it serves more than 30 million vehicle owners worldwide. The dropper carries an encrypted next-stage payload and launches a malicious downloader that contacts the attackers' command-and-control server and executes additional code.
A clicker follows, used to inflate ad impressions, and a module called zhima adds the infected head unit to a botnet. The clicker stays in contact with the command server and reports device details including model, screen resolution, MAC address, and the connected Wi-Fi network, and it can accept commands from HTTP requests to opening web pages. Kaspersky's investigation connects the botnet to residential proxy services including PXYEDGE and ProxyForU, and links the operation to the BADBOX malicious platform and its associated MoYu Group.
For drivers the impact is staged rather than existential: the head unit can slow or become less stable, and the device's internet connection degrades as traffic routes through it. Because the malware can receive commands and download further payloads, consequences depend on what the botnet operators install next. Kaspersky says its experts informed the developer, which addressed the discovered issues, and a full technical analysis is published on Securelist.












