{"id":77397,"date":"2026-08-22T18:44:35","date_gmt":"2026-08-22T22:44:35","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=77397"},"modified":"2026-08-22T18:44:35","modified_gmt":"2026-08-22T22:44:35","slug":"moyu-android-car-botnet-77397","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/moyu-android-car-botnet-77397\/","title":{"rendered":"MoYu group infects Android car head units with proxy botnet malware"},"content":{"rendered":"<p>In a significant escalation of threats targeting the Internet of Things, security researchers have uncovered a sophisticated supply-chain attack that turns <a href=\"https:\/\/www.android.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Android<\/a>a-based car head units into proxy botnet nodes. The operation, attributed to the MoYu group\u2014a threat actor previously linked to the massive BadBox malware botnet\u2014uses a legitimate device-update application to inject malware that enslaves compromised infotainment systems for <a href=\"https:\/\/overcentral.com\/en\/h96-tv-sticks-ad-fraud\/\" title=\"H96 TV Sticks Run Secret Ad Fraud and Proxy Network\" data-iacss-internal=\"1\">ad fraud and<\/a> network abuse. This marks the first documented case of a malware infection chain specifically engineered for the automotive head unit environment, signaling a troubling evolution in how cybercriminals are monetizing connected devices.<\/p>\n<h2>How the MoYu Group Compromises Android Car Head Units<\/h2>\n<p>The attack vector is both stealthy and deeply integrated into the legitimate software <a href=\"https:\/\/overcentral.com\/en\/github-pypi-supply-chain-security\/\" title=\"New GitHub, PyPI Policies Boost Supply Chain Security\" data-iacss-internal=\"1\">supply chain<\/a>. The campaign targets systems manufactured by DoFun, a Chinese automotive software and hardware provider owned by Shenzhen Driving Control Technology Co., Ltd. DoFun sells generic Android-based head units\u2014the central command consoles that manage a vehicle&#8217;s infotainment, navigation, climate, and settings systems.<\/p>\n<p>In June, Kaspersky researchers discovered a rogue APK file being downloaded from a legitimate DoFun system application called TWCore. This app normally handles device updates and maintenance, but the attackers compromised its communication channel. TWCore receives instructions through an MQTT server hosted at cardoor[.]cn, which the threat actor controls. This server orchestrates the delivery of the malicious payload, bypassing traditional security checks because the download originates from a trusted, signed application already installed on the device.<\/p>\n<p>The downloaded APK, which has no user interface, is a piece of malware named JarService. When executed, it decrypts and runs a second-stage loader that establishes a direct line of communication with a command-and-control (C2) server. This loader then downloads an additional encrypted payload, effectively creating a multi-stage infection chain designed to evade detection by static analysis tools.<\/p>\n<h3>The Technical Mechanics of JarService<\/h3>\n<p>Once the final payload is active, it begins a systematic reconnaissance of the compromised head unit. The malware periodically reports device information back to the attackers, including the device model, display resolution, Wi-Fi SSID, and MAC address. This data allows the threat actors to understand the hardware capabilities of each infected unit and tailor their monetization strategies accordingly.<\/p>\n<p>Kaspersky identified that the malware supports nine distinct commands, each serving a specific purpose in the botnet&#8217;s operations:<\/p>\n<ul>\n<li><strong>return<\/strong> \u2013 Retrieves a specified value from Android&#8217;s SharedPreferences storage, allowing the malware to read stored settings and credentials.<\/li>\n<li><strong>copy<\/strong> \u2013 Copies stored or downloaded content to the device clipboard, potentially capturing sensitive data.<\/li>\n<li><strong>http<\/strong> \u2013 Sends HTTP GET or POST requests and can save parts of the response, enabling data exfiltration and interaction with web services.<\/li>\n<li><strong>web<\/strong> \u2013 Opens a URL in a WebView and executes supplied JavaScript, which can be used to perform click fraud, render ads invisibly, or capture credentials from web forms.<\/li>\n<li><strong>loadlib<\/strong> \u2013 Not fully implemented at the time of Kaspersky&#8217;s report, suggesting the malware is still <a href=\"https:\/\/overcentral.com\/en\/microsoft-patch-tuesday-zero-day\/\" title=\"Microsoft Patches 398 Flaws, Zero-Day Under Active Attack\" data-iacss-internal=\"1\">under active<\/a> development.<\/li>\n<li><strong>loadlib2<\/strong> \u2013 Downloads and executes arbitrary code or additional modules, providing the attackers with a dynamic payload capability.<\/li>\n<li><strong>loadlib3<\/strong> \u2013 Also not fully implemented, reinforcing the developmental nature of the threat.<\/li>\n<li><strong>deeplink<\/strong> \u2013 Opens a specified resource in the browser, which can be weaponized for phishing or forced redirects.<\/li>\n<li><strong>traceroute<\/strong> \u2013 Checks whether specified hosts are reachable using ICMP ping, a technique used to map network topologies and verify connectivity for proxy operations.<\/li>\n<\/ul>\n<p>Kaspersky researchers emphasized that this malware does not interfere with driving or critical vehicle control systems. The infection is confined to the infotainment environment, but this still represents a serious privacy and security risk, as the compromised device has persistent internet access and network privileges.<\/p>\n<h2>What Is the Purpose of the Proxy Botnet on Car Head Units?<\/h2>\n<p>The ultimate goal of the MoYu group is monetization through two primary channels: advertising fraud and the operation of a residential proxy network. The malware primarily loads a reverse-proxy module named &#8220;zhima,&#8221; which effectively turns the head unit into a node in a proxy botnet. This allows the attackers to route internet traffic through the compromised devices, obfuscating the origin of malicious activities such as credential stuffing, account takeovers, and illicit site access.<\/p>\n<p>The residential proxy aspect is particularly lucrative. Internet service providers and websites treat traffic originating from residential IP addresses as more trustworthy than traffic from data centers. By routing their malicious traffic through thousands of infected car head units, the attackers can bypass geolocation restrictions, avoid IP-based blacklists, and evade fraud detection systems used by advertisers and financial institutions.<\/p>\n<p>In addition to the proxy module, the researchers observed the malware making web requests consistent with click-fraud activity. This involves simulating legitimate user clicks on advertisements to generate fraudulent revenue, a crime that costs the digital advertising industry billions of dollars annually.<\/p>\n<h3>Why Car Head Units Are an Attractive Target for Botnet Operators<\/h3>\n<p>Automotive head units present unique characteristics that make them highly desirable for botnet herders. First, they are always-on devices when the vehicle is in operation, and many remain connected to the internet even when parked, providing persistent network uptime. Second, they run a full version of Android, which offers a mature application ecosystem but also a broad attack surface. Third, these devices are rarely monitored for security updates by their owners, who typically treat them as appliances rather than computers.<\/p>\n<p>Furthermore, the supply chain for generic Android head units is fragmented and often lacks the rigorous security oversight found in consumer smartphones. Manufacturers frequently take shortcuts, such as using default credentials, failing to encrypt communications, or neglecting to patch known vulnerabilities. This creates an environment where a single breach into the update mechanism can cascade into a widespread infection across thousands of devices.<\/p>\n<p>The DoFun case is emblematic of this risk. As a provider of white-label infotainment systems, its software is installed on head units sold under various brands, making the potential reach of the MoYu campaign far greater than what might be inferred from a single vendor&#8217;s name.<\/p>\n<h2>The Connection Between MoYu and the BadBox Botnet<\/h2>\n<p>The MoYu group is not a newcomer to the cybercriminal landscape. Kaspersky&#8217;s analysis directly links this operation to the threat actor previously associated with the BadBox malware botnet, which infected over 10 million devices globally. BadBox was a sprawling botnet that similarly abused Android-based IoT devices\u2014including smart TVs, tablets, and digital signage\u2014for proxy services and ad fraud.<\/p>\n<p><a href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Google<\/a> took legal action against the operators of BadBox in 2025, aiming to disrupt the infrastructure and sinkhole the botnet&#8217;s C2 servers. However, the resurgence of MoYu with a new focus on automotive systems demonstrates the resilience of these criminal enterprises and their ability to pivot to new device categories when their existing footholds are challenged.<\/p>\n<p>This continuity suggests that the MoYu group maintains operational capacity and is actively seeking new attack surfaces. The automotive sector, with its rapid adoption of connectivity and relatively immature security practices, represents a fertile ground for exploitation.<\/p>\n<h3>How the Infection Was Discovered and What Happens Next<\/h3>\n<p>The discovery was made by Kaspersky researchers in June, during routine threat hunting activities. They observed anomalous traffic originating from DoFun head units and traced it back to the compromised TWCore application. The researchers notified DoFun of their findings, and the Chinese firm confirmed that it had resolved the problem. However, the company did not provide details regarding the initial compromise vector\u2014specifically, how the attackers gained the ability to inject malicious updates through the legitimate app.<\/p>\n<p>This lack of transparency raises important questions. If the vulnerability was in DoFun&#8217;s cloud infrastructure, the same weakness could be exploited by other threat actors. If it was a credential compromise, the attackers may retain alternative access paths. BleepingComputer has contacted both Kaspersky and DoFun for clarification on these points, and updates will be provided as more information becomes available.<\/p>\n<h2>What Android Car Head Unit Users Need to Know<\/h2>\n<p>For owners of Android-based car infotainment systems, especially those sourced from generic or third-party manufacturers, several practical steps can reduce the risk of infection. First, disable automatic updates if the device does not allow verification of the update source. Second, monitor network traffic for unusual data usage\u2014proxy botnets consume bandwidth even when the device is idle. Third, use a firewall or network-level monitoring tool to detect unexpected outbound connections, particularly to known malicious domains or MQTT servers.<\/p>\n<p>It is also advisable to research the manufacturer&#8217;s security track record before purchasing a head unit. Brands that provide regular firmware updates with clear changelogs and vulnerability disclosures are generally more trustworthy than those that ship devices and abandon them. For aftermarket installations, consider using a dedicated cellular hotspot rather than connecting the head unit directly to a home or mobile network, as this limits the device&#8217;s ability to communicate with C2 servers.<\/p>\n<p>Importantly, users should be aware that the malware described here does not affect driving safety systems. The infection remains contained within the infotainment OS, which runs in a separate environment from the vehicle&#8217;s engine control unit (ECU) or advanced driver-assistance systems (ADAS). However, the privacy implications are severe\u2014compromised head units can potentially access contacts, call logs, location data, and even microphone or camera feeds if those are integrated into the infotainment system.<\/p>\n<h2>What Are the Broader Implications for IoT Security?<\/h2>\n<p>The MoYu supply-chain attack on car head units underscores a fundamental weakness in the IoT ecosystem: the reliance on third-party components with opaque security practices. When a single software provider&#8217;s update mechanism is breached, the damage cascades across all downstream devices, regardless of the brand name on the box.<\/p>\n<p>This incident also highlights the growing sophistication of cybercriminal supply-chain operations. The attackers did not simply scan for vulnerable devices on the internet; they subverted the trusted update path itself. This approach is far more difficult to detect because the malicious payload is delivered through a legitimate, signed application, bypassing signature-based antivirus solutions and app store vetting processes.<\/p>\n<p>For the automotive industry, this marks a wake-up call. As vehicles become increasingly connected and software-defined, the attack surface expands dramatically. Regulators in the European Union and the United States are beginning to mandate cybersecurity management systems for vehicles, but these frameworks are still evolving. In the interim, manufacturers must conduct thorough security audits of their entire supply chain, including third-party software libraries, cloud services, and update mechanisms.<\/p>\n<p>The MoYu group&#8217;s ability to pivot from consumer electronics to automotive infotainment suggests that no connected device is immune. The same monetization model\u2014turn devices into proxy nodes and ad-fraud engines\u2014can be applied to any Android-based system with persistent network access. This includes smart displays, refrigerators, thermostats, and even medical devices that run on the Android Open Source Project.<\/p>\n<p>As the lines between consumer devices, enterprise tools, and automotive systems continue to blur, the demand for robust, proactive IoT security has never been more urgent. The discovery of this malware campaign, while alarming, also serves as an opportunity for the industry to learn from the vulnerabilities exposed and to implement more resilient architectures before the next wave of attacks begins.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In a significant escalation of threats targeting the Internet of Things, security researchers have uncovered a sophisticated supply-chain attack that turns Androida-based car head units into proxy botnet nodes. The operation, attributed to the MoYu group\u2014a threat actor previously linked to the massive BadBox malware botnet\u2014uses a legitimate device-update application to inject malware that enslaves [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":82789,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/77397.png","fifu_image_alt":"MoYu group infects Android car head units with proxy botnet malware","footnotes":""},"categories":[40668],"tags":[],"class_list":["post-77397","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/77397.png","fifu_image_alt":"MoYu group infects Android car head units with proxy botnet malware","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/77397","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=77397"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/77397\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/82789"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=77397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=77397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=77397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}