Particle.news

Android Car Head Units Hijacked Through Trusted Updater to Join Proxy Botnet

Researchers say attackers abused a system updater to install a reverse-proxy module that turns always-online head units into rented proxy nodes and ad-fraud engines.

Overview

  • Kaspersky published technical findings in late August showing attackers used the TWCore system updater and its message broker to push malicious APKs to DoFun firmware on Android head units.
  • The infection runs in three stages: a JarService dropper, a loader that gathers device info, and a periodic check-in stage that downloads a reverse-proxy module called zhima.
  • The malware uses TWCore’s installNotExists flag to install apps silently, and observed payloads perform background ad-fraud and proxy traffic routing without affecting vehicle driving systems.
  • Kaspersky links the operation with high confidence to the MoYu Group and the BADBOX ecosystem, and Nokia’s Deepfield team found the same zhima module on TV set-top boxes, suggesting a cross-device campaign.
  • DoFun says it has patched the vulnerable update channel after responsible disclosure, but researchers warn the full scope and whether other head-unit vendors are affected remain unclear and hard for owners to verify.