Hackers Hijack Smart Car Displays via Fake Android Updates
Cybersecurity researchers at Kaspersky have uncovered a sophisticated malware campaign targeting Android-based automotive head units, marking the first documented case of malicious code explicitly engineered to compromise vehicle infotainment systems for ad fraud.
The discovered attack disguises itself as legitimate software updates to covertly deploy backdoors on dashboards. Rather than tricking drivers into manually downloading malicious apps, attackers breached the update channel of a legitimate system component called TWCore, which is responsible for collecting device telemetry and pushing OTA (Over-The-Air) system updates via an MQTT server hosted on cardoor[.]cn.
By manipulating a configuration setting known as installNotExists, the malicious actor forced the server to quietly install arbitrary application packages without triggering user prompts or UI notifications. The primary payload, labeled JarService, establishes communication with a remote command-and-control server and transmits sensitive system metrics, including the car unit's model, screen resolution, MAC address, and Wi-Fi network identifier.
The infection chain then fetches secondary payloads, most notably a module named zhima. This module turns the infected infotainment system into a reverse proxy node, routing external web traffic through the vehicle's active cellular or Wi-Fi data connection. This allows threat actors to mask malicious online traffic, conduct automated click fraud, and lease residential proxy bandwidth to paying subscribers.
Investigative overlap in infrastructure, command structures, and internal code artifacts connects this automotive campaign to the MoYu Group, a threat actor affiliated with the notorious BadBox botnet. Historically known for infecting cheap Android TV streaming boxes and mobile devices straight from factory supply chains, BadBox operations have unfortunately expanded into automotive ecosystems to exploit persistent internet connections and low threat-monitoring coverage in cars.
Kaspersky noted direct links between the campaign's command servers and administrative portals for commercial proxy platforms like ProxyForU and PXYEDGE. Following notification by Kaspersky (which also runs the banned antivirus software), DoFun has reportedly addressed the vulnerability affecting their firmware.