Android Car Head Units Turned Into Proxy Bots by MoYu Supply-Chain Attack

Kaspersky researchers have discovered a supply-chain attack that infects Android-based car head units by abusing a legitimate device-update app. The operation, attributed to the MoYu threat group previously linked to the BadBox botnet, marks the first documented malware infection chain built specifically for car infotainment systems. The attack targets head units from DoFun, a Chinese automotive software and hardware provider owned by Shenzhen Driving Control Technology.

The infection begins when a rogue APK called JarService is downloaded through TWCore, a legitimate DoFun system app that receives instructions via an MQTT server. The interfaceless malware decrypts and runs a second-stage loader that connects to a command-and-control server and fetches an encrypted payload. The final payload periodically reports device details such as model, display resolution, Wi-Fi SSID, and MAC address, and supports nine commands including HTTP requests, clipboard copying, opening URLs with JavaScript execution, downloading arbitrary code, and running traceroute checks.

Kaspersky says the malware does not interfere with driving or critical vehicle control systems. Instead, it appears designed for advertising fraud and for turning internet-connected head units into residential proxy nodes that can be monetized by the attackers. The discovery highlights how increasingly connected car systems are becoming attractive targets for cybercriminal operations focused on monetization rather than direct vehicle manipulation.

Read More at the original source →