Particle.news

Android Car Head Units Hijacked Into Proxy Botnet Via Built‑In Updater

Researchers say attackers abused a trusted updater to install a three‑stage Android malware that turns head units into ad‑fraud engines that route other people’s internet traffic.

Overview

  • Researchers publicly documented the campaign Monday after tracing a three‑stage chain: a dropper called JarService, a loader that fetches payloads, and a final payload that installs a 'zhima' reverse‑proxy module.
  • The infection exploits TWCore, a legitimate system updater that reads instructions from a message broker on cardoor[.]cn and uses an installNotExists flag to push apps without user action.
  • Kaspersky attributes the operation with high confidence to the MoYu Group linked to the BADBOX ecosystem and Nokia Deepfield found the same zhima module on TV set‑top boxes, showing the campaign targets multiple consumer devices.
  • DoFun, the vendor whose DoFun firmware was affected, says it has closed the updater vulnerability after being notified, but owners have no easy way to check or remove persistent system‑level infections.
  • This case shows how always‑connected aftermarket head units with cellular or Wi‑Fi can be monetized by attackers for ad fraud and proxy services and raises the risk that more low‑cost connected devices will be recruited into similar botnets.