{"id":2492,"date":"2026-08-21T17:53:13","date_gmt":"2026-08-21T17:53:13","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2492"},"modified":"2026-08-21T17:53:13","modified_gmt":"2026-08-21T17:53:13","slug":"android-car-malware-spreads-through-built-in-updaters-for-ad-fraud-proxy-botnet","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2492","title":{"rendered":"Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 21, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Automotive Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi1EQE-DqLXTzpjwGf3nQnM4CTnjibkKl_2ersn8abw3Gmqoc5MUaFC2LvkA7c6Xoa0XBPZeHL4wHHiXU7Pc9nGLcI1zTorwFTwvYXfww4Q68oSUrgcQhmBzQBNqYp-woIZFK_I1OOsnBNptiwA90VHhpE_hvlz3qdFomOmOMLreYe5YCenvR2CeawvRrMU\/s1700-e365\/car.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>Cybersecurity researchers have flagged a new malware family that&#8217;s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.<\/p>\n<p>Kaspersky, which <a href=\"https:\/\/securelist.com\/android-head-unit-malware\/121106\/\" target=\"_blank\">discovered<\/a> the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.<\/p>\n<p>\u00abThe malware spread through the built-in updaters of Android-based automotive head unit firmware,\u00bb security researcher Dmitry Kalinin said. \u00abThis is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.\u00bb<\/p>\n<p>The activity has been attributed with high confidence to the MoYu Group, which was outed by the HUMAN Satori Threat Intelligence and Research team last year as part of a broader ad fraud and residential proxy scheme dubbed BADBOX. In July 2025, Google filed a lawsuit against 25 unnamed individuals or entities in China for allegedly operating the BADBOX botnet and its infrastructure.<\/p>\n<p>A car head unit is a central hub that combines multimedia functions with partial control over certain vehicle functions. It can be factory-installed or fitted on older vehicles as part of an aftermarket upgrade. Because Android-powered card head units have <a href=\"https:\/\/www.fortunebusinessinsights.com\/automotive-operating-system-market-109026\" target=\"_blank\">become popular<\/a> across both aftermarket retrofits and factory-built vehicles, a huge chunk of the standard apps, and by extension, malware, can also run on them.<\/p>\n<p>This, in turn, makes them an emerging target for bad actors, as they feature a SIM card slot that enables internet access for navigation and software updates.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe delivery methods for such malware are becoming highly varied \u2013 ranging from pre-installed backdoors to compromised IPTV applications,\u00bb Kalinin said in a statement shared with The Hacker News. \u00abIn this researched case, we observed an even more sophisticated delivery method exploiting the legitimate software update functionality of a system app.\u00bb<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Specifically, this involves distributing the malware via the update mechanisms built into the firmware of multiple models of Android-based head units powered by DoFun. Following responsible disclosure, the issue driving the software distribution abuse has been addressed.<\/p>\n<p>The starting point is a legitimate system app called TWCore (\u00abcom.tw.core\u00bb), which is designed to collect analytics and update the head unit&#8217;s software in the form of APK files by making use of a MQTT message broker hosted on the \u00abcardoor[.]cn\u00bb subdomain. The APK file is downloaded to the \u00ab<twcore external=\"\" cache=\"\" dir=\"\">\/push\/apk\/\u00bb path for installation.<\/twcore><\/p>\n<p>The threat actors behind the campaign are said to have weaponized this update channel to deliver previously unknown malware directly to the head units using a dropper dubbed JarService, while taking steps to evade detection. The dropper is responsible for launching a loader that performs the following actions &#8211;<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjGjX8DqkkY7IiY7RAvhxpu_ejsjnlr87a2rgHJuv2lfyBriUuVOLH0g6IdUwsse1oH29fHpC58P8_Ugj5zw3QNonJNya2bHrxLX9trSn9dSzEpiqJn4g4Zh4O8kT1t6o25_8FsxhZFWbaktYA-_7JS98zFmL57DKRkmYl63SUbk3GC3eAcQ7MNHbkOxS6I\/s1700-e365\/jar.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjGjX8DqkkY7IiY7RAvhxpu_ejsjnlr87a2rgHJuv2lfyBriUuVOLH0g6IdUwsse1oH29fHpC58P8_Ugj5zw3QNonJNya2bHrxLX9trSn9dSzEpiqJn4g4Zh4O8kT1t6o25_8FsxhZFWbaktYA-_7JS98zFmL57DKRkmYl63SUbk3GC3eAcQ7MNHbkOxS6I\/s1700-e365\/jar.png\" alt=\"\" border=\"0\" data-original-height=\"881\" data-original-width=\"1632\"\/><\/a><\/div>\n<ul style=\"text-align: left;\">\n<li>Sends implant information to one of the attackers servers via an HTTP POST request<\/li>\n<li>Server responds with a link for downloading the next-stage payload (\u00ab144.217.243[.]201\/vr34der34\/dex3.68.png\u00bb)<\/li>\n<\/ul>\n<p>The payload name includes a reference to a version number (\u00abdex3.68\u00bb), allowing Kaspersky to retrieve seven distinct variants dating back to \u00ab3.57\u00bb simply by trying other version numbers.<\/p>\n<p>The attack chain ends with the deployment of the malware as a regular user application. However, it lacks a user interface and covertly operates in the background. It&#8217;s configured to send a POST request to the command-and-control (C2) endpoint (\u00ab\/cpc\/api\/task\u00bb) every 90 minutes by default, along with information about the infected device and its configuration version.<\/p>\n<p>\u00abIf the configuration is outdated, the C2 server returns an updated configuration containing new C2 addresses and new paths for sending HTTP requests,\u00bb Kaspersky said. \u00abIf the configuration version doesn&#8217;t need updating, the C2 server instead returns integer command identifiers, which the attackers refer to as productId.\u00bb<\/p>\n<p>\u00abThe Trojan maps each identifier to command information, which it stores as a serialized JSON object using the SharedPreferences API.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The malware supports nine commands capable of displaying unwanted advertisements, executing ad fraud, and downloading additional malicious modules. It also allows attackers to receive extensive device information, including display resolution, device model, connected Wi-Fi network identifier, and MAC address. The list of commands is below &#8211;<\/p>\n<ul>\n<li><strong>return<\/strong>, to return a value from SharedPreferences<\/li>\n<li><strong>copy<\/strong>, to set clipboard contents<\/li>\n<li><strong>http<\/strong>, to make a POST\/GET HTTP request to a specified resource<\/li>\n<li><strong>web<\/strong>, to open a link in WebView and execute arbitrary JavaScript code within it<\/li>\n<li><strong>loadlib<\/strong> (not fully implemented)<\/li>\n<li><strong>loadlib2<\/strong>, to download and execute arbitrary code from an URL<\/li>\n<li><strong>loadlib3<\/strong> (not fully implemented)<\/li>\n<li><strong>deeplink<\/strong>, to open a URL in the browser<\/li>\n<li><strong>traceroute<\/strong>, to check resource availability via an ICMP ping<\/li>\n<\/ul>\n<p>The threat actors have been found to leverage \u00abloadlib2\u00bb and \u00abhttp\u00bb commands to download \u00ab<a href=\"https:\/\/github.com\/deepfield\/public-research\/blob\/main\/ipmoyu\/report.md\" target=\"_blank\">zhima<\/a>,\u00bb a reverse proxy module documented by Nokia Deepfield Emergency Response Team last month and selectively delivered via IPTV apps installed in cheap Android TV boxes.<\/p>\n<p>\u00abDespite the efforts of cybersecurity experts and law enforcement agencies to shut down the BADBOX botnet, individual actors associated with it continue their malicious activities, infecting devices worldwide,\u00bb Kalinin said.<\/p>\n<p>\u00abThis malware has become the very first malicious application specifically targeting car head units through an infection chain explicitly tailored for these vehicle systems. This serves as a warning that modern automotive platforms urgently require robust protection against malware.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 21, 2026Malware \/ Automotive Security Cybersecurity researchers have flagged a new malware family that&#8217;s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2493,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[281,192,3126,3125,250,42,354,666,3127],"class_list":["post-2492","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-android","tag-botnet","tag-builtin","tag-car","tag-fraud","tag-malware","tag-proxy","tag-spreads","tag-updaters"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2492"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2492\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2493"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}