HomeBreachedYour Car's Infotainment System Has Been Hijacked: First-Ever Android Malware Targets Vehicle...

Your Car’s Infotainment System Has Been Hijacked: First-Ever Android Malware Targets Vehicle Head Units

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

You’re driving to work, your favorite playlist streaming through the car’s speakers, the navigation system calmly directing you through traffic. Everything looks normal. Everything feels normal. But beneath that familiar dashboard interface, something is very, very wrong. Your car’s infotainment system is quietly reporting your device’s unique identifiers to a remote server. It’s downloading encrypted modules in the background. And it’s turning your vehicle’s internet connection into a node in a global proxy botnet all without you ever knowing, and without leaving a single trace on the screen.

Imagine driving down the highway, your car’s navigation system guiding you to your destination. You’re listening to music, adjusting the climate control, maybe even checking the weather. Everything seems normal.

But in the background, your car’s infotainment system is quietly reporting your device’s information to a remote server. It’s downloading hidden modules. And it’s turning your vehicle’s internet connection into a node in a global proxy botnet, all without you ever knowing.

This isn’t science fiction. It’s the reality uncovered by Kaspersky researchers in June 2026, who identified the first documented case of malware specifically designed to target Android-based automotive head units, according to Securelist.

“This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device,” said Dmitry Kalinin, security researcher at Kaspersky .

The campaign, attributed with high confidence to the MoYu Group – a threat actor linked to the infamous BADBOX botnet – has compromised thousands of vehicle infotainment systems worldwide through a sophisticated supply-chain attack.

The Attack Chain: How Your Car Got Infected

The infection doesn’t come from a malicious app you downloaded or a suspicious link you clicked. Instead, the attackers weaponized a legitimate system application called TWCore, which is responsible for collecting analytics and updating the head unit’s software.

Here’s how the infection chain works :

Stage 1: The Legitimate Update Channel

TWCore receives instructions from an MQTT message broker hosted on cardoor[.]cn. These instructions tell the app which APK files need to be downloaded and installed on the head unit. The attackers exploited a flag called installNotExists, which allowed TWCore to install apps that weren’t originally present on the device.

Stage 2: The JarService Dropper

The malicious APK downloaded through this channel is called JarService. It has no user interface, no icon, no window, no indication it exists. It quietly decrypts encrypted data within its own code and launches the next stage of the attack.

Stage 3: The Loader

The second-stage loader sends device information to the attackers’ command-and-control (C2) server via a POST request. The C2 responds with a link to download the third-stage payload.

Stage 4: The Payload

The final payload is a clicker and reverse proxy module. It sends device information to the C2 every 90 minutes and can execute nine different commands, including downloading additional modules and making HTTP requests.

What the Malware Does

Once fully installed, the malware operates entirely in the background, invisible to the user. Its capabilities include :

  • Ad Fraud: Displaying unwanted advertisements and committing click fraud
  • Proxy Botnet: Installing a reverse proxy module called “zhima” that turns the head unit into a residential proxy node
  • Information Theft: Collecting device model, screen resolution, Wi-Fi SSID, and MAC address
  • Remote Control: Executing commands such as opening URLs in WebView, copying clipboard contents, and downloading additional malicious code

The attackers primarily used two commands in real-world attacks: loadlib2 to download and execute arbitrary code, and http to send web requests.

Why Car Head Units?

Automotive head units have become an attractive target for cybercriminals for several reasons:

Constant Internet Connectivity: Most head units include SIM card slots and maintain continuous internet connections for navigation, traffic updates, and software updates.

Low User Interaction: Unlike smartphones, users don’t routinely check their car’s infotainment system for suspicious activity. The malware can operate without detection for extended periods.

Growing Installed Base: Android-based head units have become popular in both factory-installed and aftermarket systems, creating a large target population.

Limited Security Focus: Until now, automotive infotainment systems haven’t been a primary focus for cybersecurity researchers or manufacturers.

The attackers identified a perfect use case: turn these devices into proxy nodes for monetization. As Kaspersky noted, since head units typically hold nothing of value to an attacker, recruiting them into a botnet is one of the most profitable scenarios.

Attribution: The MoYu Group Connection

Kaspersky attributes this campaign with high confidence to the MoYu Group, a threat actor linked to the BADBOX botnet .

The connection was uncovered through several clues:

  • A thread named mosdk-host-loader in the stage 2 loader code led researchers to a malicious app with a component named AdmoyuService
  • The infrastructure overlap with previously identified MoYu Group operations was significant
  • The malware’s administration panel, hosted at admin.uipoxy[.]com, shares artifacts with residential proxy service websites PXYEDGE and ProxyForU

This campaign shows that despite law enforcement efforts to shut down the BADBOX botnet, individual actors continue their malicious activities, expanding into new platforms.

What This Means for Vehicle Owners

If you own a vehicle with an Android-based head unit – particularly if it’s a DoFun-branded system – your device may be compromised . Since DoFun supplies systems to multiple brands and aftermarket providers, the reach of this campaign could be extensive.

Warning signs to watch for :

  • Unexpected appearance of unfamiliar advertisements
  • Noticeable system lag or decreased performance
  • Unexplained data usage
  • Presence of unknown installed applications

The malware doesn’t appear to interfere with driving or critical vehicle control systems, but its ability to download additional modules presents a risk of deeper system compromise.

10 Urgent Actions for Vehicle Manufacturers, Fleet Operators, and Owners

For Manufacturers and Fleet Operators:

1. Audit the Update Distribution Chain
Review all system applications involved in firmware updates. Ensure that flags like installNotExists cannot be abused to install unauthorized applications.

2. Implement Code Signing Verification
All updates should be cryptographically signed and verified before installation. The TWCore app should only install APKs signed with manufacturer certificates.

3. Monitor MQTT and Update Traffic
Monitor network traffic to update servers for unauthorized commands. The attackers used cardoor[.]cn as a C2; similar abuse could occur on other platforms.

4. Develop a Head Unit Security Standard
Establish security requirements for Android-based head units, including regular security audits and penetration testing.

For Vehicle Owners:

5. Check for Unknown Applications
Review the list of installed applications on your head unit. Look for any apps you don’t recognize, particularly those without an icon.

6. Limit Network Exposure
If possible, disable features you don’t use, such as P2P or unnecessary network services. Consider using a VPN to protect your vehicle’s internet traffic.

7. Reset to Factory Defaults
If you suspect compromise, perform a factory reset. Be aware that some backdoors may survive resets, so this isn’t a guaranteed solution.

8. Contact Your Dealer
If you notice suspicious behavior, contact your vehicle dealer or the manufacturer’s support line. Ask whether your head unit model was affected by this campaign.

For All Stakeholders:

9. Report Suspicious Activity
Report any suspicious behavior to your vehicle manufacturer and relevant CERT. Sharing information helps the entire industry respond.

10. Stay Informed
Follow cybersecurity news related to connected vehicles. As this campaign shows, automotive cybersecurity is an emerging threat landscape that requires vigilance.

The Bigger Picture: Connected Vehicles as Cyber Battleground

This campaign represents a significant milestone in the evolution of cyber threats. Attackers are moving beyond smartphones and IoT devices to target specialized platforms, including vehicles.

The MoYu Group’s operation also demonstrates a troubling trend: the commercialization of botnets. The registration page for the malware’s administration panel requires an invitation code, suggesting this is a commercial operation where access is sold to other cybercriminals .

“The delivery methods for such malware are becoming highly varied – ranging from pre-installed backdoors to compromised IPTV applications. In this researched case, we observed an even more sophisticated delivery method exploiting the legitimate software update functionality of a system app,” Kalinin warned .

Conclusion

The discovery of malware targeting Android-based vehicle head units marks a new frontier in cybersecurity threats. For the first time, a malicious actor has designed a complete infection chain specifically for automotive systems, exploiting the legitimate update mechanism to silently compromise thousands of vehicles.

While this particular campaign focuses on ad fraud and proxy botnets, the implications are wider. If attackers can compromise the infotainment system – which often has partial control over certain vehicle functions – what’s next?

For vehicle manufacturers, this is a wake-up call: connected vehicles require the same security focus as other critical systems. For vehicle owners, it’s a reminder that cybersecurity extends beyond your smartphone and laptop. Your car is a computer, too.

The BADBOX botnet may have been disrupted, but the MoYu Group and similar threat actors are adapting, evolving, and expanding into new platforms. The question isn’t whether attackers will target your vehicle, it’s whether you’ll know when they do.

For more cybersecurity news and analysis, visit CyberCory.com, your trusted source for security intelligence. For comprehensive cybersecurity training and awareness programs, explore solutions at Saintynet.com.

Ouaissou DEMBELE
Ouaissou DEMBELE
Ouaissou DEMBELE is a seasoned cybersecurity expert with over 12 years of experience, specializing in purple teaming, governance, risk management, and compliance (GRC). He currently serves as Co-founder & Group CEO of Sainttly Group, a UAE-based conglomerate comprising Saintynet Cybersecurity, Cybercory.com, and CISO Paradise. At Saintynet, where he also acts as General Manager, Ouaissou leads the company’s cybersecurity vision—developing long-term strategies, ensuring regulatory compliance, and guiding clients in identifying and mitigating evolving threats. As CEO, his mission is to empower organizations with resilient, future-ready cybersecurity frameworks while driving innovation, trust, and strategic value across Sainttly Group’s divisions. Before founding Saintynet, Ouaissou held various consulting roles across the MEA region, collaborating with global organizations on security architecture, operations, and compliance programs. He is also an experienced speaker and trainer, frequently sharing his insights at industry conferences and professional events. Ouaissou holds and teaches multiple certifications, including CCNP Security, CEH, CISSP, CISM, CCSP, Security+, ITILv4, PMP, and ISO 27001, in addition to a Master’s Diploma in Network Security (2013). Through his deep expertise and leadership, Ouaissou plays a pivotal role at Cybercory.com as Editor-in-Chief, and remains a trusted advisor to organizations seeking to elevate their cybersecurity posture and resilience in an increasingly complex threat landscape.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img