VYPR
researchPublished Aug 24, 2026· 1 source

Hackers Turn Android Car Systems into Proxy Botnet

A new malware campaign is compromising Android-based automotive infotainment systems, repurposing them to form a proxy botnet for malicious traffic routing.

Researchers have uncovered a novel malware campaign that targets and infects Android-based automotive infotainment systems, effectively transforming these vehicle components into a proxy botnet. This sophisticated operation allows malicious actors to route their internet traffic through compromised cars, obscuring the origin of their illicit activities.

The campaign specifically targets head units, the central computing and display systems in vehicles responsible for navigation, audio, and connectivity. Kaspersky, the cybersecurity firm that detailed the findings, identified the infections on head units manufactured by DoFun, a Chinese provider of automotive software and hardware. This marks the first documented instance of malware specifically designed to infect car head units through such an attack vector, deviating from previous methods that often relied on physical access or broader operating system vulnerabilities.

Attackers exploited a legitimate system application named TWCore, which is pre-installed on DoFun devices. TWCore is designed for collecting analytics and managing software updates, including the capability to download and install new Android applications. By abusing this functionality, threat actors were able to push a malicious application, dubbed JarService, onto affected devices without any user interaction, such as clicking links or visiting malicious websites.

JarService operates discreetly, lacking any visible user interface, which makes it exceedingly difficult for vehicle owners to detect a compromise. While the malware is capable of displaying advertisements and generating fraudulent ad clicks, its primary objective appears to be the expansion of a botnet. These botnets are networks of compromised devices that criminals can control remotely for various nefarious purposes, including cyberattacks, fraud, and traffic redirection.

One of the key modules identified within the malware enables infected head units to function as reverse proxies. This functionality allows external internet traffic to be channeled through the compromised vehicle's connection, effectively masking the true source of the malicious activity. This makes attribution and takedown efforts significantly more challenging for cybersecurity professionals.

Kaspersky attributes this campaign with a high degree of confidence to the MoYu Group, a threat actor previously linked to the BadBox malware operation. The MoYu Group has a history of compromising various Android devices, including smartphones, tablets, and other internet-connected products. Their previous operations have demonstrated a pattern of distributing malware through pre-installed software on devices before they reach consumers.

This new campaign emerges even as efforts to combat the BadBox botnet continue. Despite law enforcement actions and cybersecurity initiatives aimed at disrupting the BadBox infrastructure, individual actors associated with the group have persisted in their malicious activities. This highlights the adaptive nature of cybercriminal organizations and their ability to evolve their tactics and infrastructure.

The FBI had previously issued warnings about BadBox 2.0 targeting a wide range of Internet of Things (IoT) devices, including streaming boxes, projectors, and aftermarket vehicle infotainment systems. The recent discovery of this automotive-specific malware underscores the expanding reach and evolving targets of these persistent threat actors.

Synthesized by Vypr AI