Key Takeaways
- Kaspersky identified the first known malware specifically designed to infect Android‑based car head units, affecting devices supplied by Chinese vendor DoFun.
- The abuse vector is the legitimate system app TWCore, which attackers hijacked to silently install a downloader called JarService without any user interaction.
- JarService operates invisibly, downloading additional malicious modules that generate fraudulent ad clicks and turn the head unit into a reverse proxy for routing other users’ internet traffic.
- The campaign is attributed with high confidence to the threat actor MoYu Group, linked to the long‑running BadBox botnet operation that has previously compromised smartphones, tablets, TV boxes, and IoT devices.
- Although German authorities disrupted the original BadBox infrastructure in December 2024, the actors quickly resurrected an updated version, and the FBI has warned that BadBox 2.0 now targets a broad range of IoT products, including aftermarket vehicle infotainment systems.
- The discovery underscores the growing attack surface of connected automobiles and the need for vendors to harden over‑the‑air update mechanisms and monitor legitimate system apps for abuse.
Introduction
Researchers from Russian cybersecurity firm Kaspersky have reported a novel malware campaign that infects Android‑based head units in automobiles, turning the infotainment systems into nodes of a botnet. The finding marks the first documented instance where threat actors have specifically designed an attack for car multimedia systems, rather than relying on physical access or generic OS vulnerabilities.
Vendor and Device Scope
The compromised head units were manufactured by DoFun, a Chinese provider of automotive software and hardware. These units integrate navigation, music playback, Bluetooth connectivity, and other infotainment functions, all running a customized Android environment. Because the head units serve as the central interface for driver‑vehicle interaction, their compromise poses both safety and privacy concerns.
Attack Vector: Abusing TWCore
Kaspersky traced the infection pathway to a legitimate system application named TWCore, pre‑installed on DoFun devices. TWCore normally collects analytics data and manages over‑the‑air software updates; it also possesses the capability to download and install new Android applications. Attackers exploited this update mechanism to push a malicious payload without requiring the driver to click a link, visit a malicious site, or manually install anything.
The Malicious Downloader: JarService
The payload delivered via TWCore is an app called JarService. JarService has no visible user interface, making it difficult for drivers to detect its presence. Its primary role is to act as a downloader, silently retrieving and installing additional malicious modules onto the head unit once it gains a foothold on the device.
Malicious Capabilities
Beyond serving as a downloader, the malware suite performs several harmful actions. It can display advertisements and generate fraudulent ad clicks, providing a revenue stream for the operators. More significantly, one observed module converts the infected head unit into a reverse proxy, allowing external internet traffic to be routed through the car’s network connection. This obscures the true origin of the traffic and can be used for illicit activities such as credential stuffing, Distributed Denial‑of‑Service (DDoS) attacks, or traffic‑routing fraud.
Botnet Formation and Reverse Proxy Function
By enslaving numerous head units, the attackers build a distributed botnet composed of automotive IoT devices. The reverse‑proxy capability is especially valuable because it leverages the often‑trusted IP addresses associated with vehicle cellular connections, making malicious traffic appear to emanate from legitimate consumer devices rather than from known hostile infrastructure.
Attribution to MoYu Group and BadBox
Kaspersky attributes the campaign with high confidence to MoYu Group, a threat actor historically linked to the BadBox malware operation. BadBox has previously compromised Android smartphones, tablets, streaming boxes, and other internet‑connected products, often by pre‑installing malware on devices before they reach consumers. The similarity in tactics, techniques, and infrastructure led researchers to confidently connect the car‑head‑unit infection to the same criminal enterprise.
Historical Context of BadBox
In 2023, security firm HUMAN Security reported discovering more than 70,000 Android smartphones, connected TV boxes, and tablets from at least one Chinese manufacturer that shipped with BadBox‑linked malware. The operation demonstrated a supply‑chain compromise strategy, embedding malicious code during the manufacturing or distribution phase.
Disruption and Resurgence
German law‑enforcement authorities disrupted the original BadBox botnet in December 2024 by severing communications between infected devices and the attackers’ command‑and‑control (C2) infrastructure. Despite this setback, the threat actors rapidly resurfaced with an updated version of the botnet, indicating a resilient and adaptive criminal operation.
FBI Warning on BadBox 2.0
The Federal Bureau of Investigation (FBI) issued a warning last year that BadBox 2.0 is now targeting a broader array of Internet‑of‑Things (IoT) devices. The advisory highlighted threats to TV streaming boxes, digital projectors, digital picture frames, and aftermarket vehicle infotainment systems—precisely the class of devices implicated in the current DoFun head‑unit infection. The FBI’s alert underscores the expanding scope of the BadBox enterprise beyond traditional mobile devices.
Implications for Automotive Cybersecurity
The discovery of malware specifically engineered for car head units signals a shift in the threat landscape for connected vehicles. Manufacturers and suppliers must reconsider the security of legitimate system apps like TWCore, implement stricter code‑signing and integrity checks for over‑the‑air updates, and employ runtime monitoring to detect anomalous behavior such as silent app installations or unexpected network proxying. Additionally, vehicle owners should be advised to keep their infotainment software up to date and to be wary of unexplained performance changes or excessive data usage.
Conclusion
Kaspersky’s report reveals a sophisticated, supply‑chain‑style attack that leverages a trusted update mechanism to infiltrate Android‑based car infotainment systems, converting them into botnet nodes capable of ad fraud and traffic relaying. The operation’s linkage to the established BadBox campaign and its rapid rebound after law‑enforcement disruption illustrate the persistence and adaptability of the threat actors involved. As automobiles become increasingly connected, securing the software supply chain and monitoring legitimate system components for abuse will be critical to preventing similar incidents in the future.

