Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet
Hackers exploited trusted software updates to deliver malware directly into car head units Kaspersky says this is the first campaign tailored specifically for vehicle head units The malware can run silently without showing drivers any visible interface Car head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.
A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.
According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.
Compromised update channels deliver malware straight into vehicles Researchers believe the activity can likely be traced back to the MoYu Group, a threat actor closely tied to the well-known BadBox botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by DoFun.
The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.
Attackers hijacked this trusted update channel using a specialized dropper called JarService to deliver previously unknown malware directly onto a range of affected devices.
Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.
Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.
The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device's MAC address.
Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.
The research team claims that the botnet's administration panel shares embedded URLs with residential proxy service websites PXYEDGE and ProxyForU.
BadBox itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.
Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.
According to statements from DoFun, the underlying issue has since been resolved across most affected devices currently deployed in the field.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.