Kaspersky researchers uncovered a supply chain attack infecting Android-based car head units with malware designed for ad fraud and proxy botnet activity.
The malware was distributed through the built-in updater of TWCore, a legitimate system application installed on head units from Chinese automotive technology provider DoFun. Researchers said this is the first documented malware infection chain specifically designed to target automotive head units.
The attack uses a three-stage infection chain, beginning when the legitimate updater downloads a malicious APK. Once installed, additional malware components are retrieved that can generate fraudulent advertising activity and turn the vehicle’s internet connection into a proxy for other traffic.
The threat is imminent. Today’s notice of the critical Keycloak Password Reset Flaw (CVE-2026-18963, CVSS 9.1) exposes thousands of enterprise identity servers to risk of complete, unauthenticated takeover.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“MoYu Group, the same actor behind BADBOX infections on cheap Android TV set-top boxes, expanded to car dashboards because to a residential proxy operator, any Android device with a Subscriber Identity Module (SIM) card is just inventory.
“DoFun’s TWCore updater accepts instructions from a Message Queuing Telemetry Transport (MQTT) broker and includes a flag called installNotExists that lets the server push entirely new applications to the device without human approval. The attackers pushed malware through this privileged deployment channel exactly as it was designed to work.
“The zhima proxy module on these head units ties back to residential proxy services PXYEDGE and ProxyForU, both connected to MoYu Group’s broader infrastructure. Compromised vehicles are being sold as proxy endpoints to whoever pays. A car sitting in a parking lot becomes someone else’s exit node, routing traffic through a cellular connection the vehicle owner pays for.
“Every original equipment manufacturer (OEM) sourcing Android-based head units from third-party firmware providers should be asking who audited the update channel before it shipped. Arbitrary code delivery already works through loadlib2, while loadlib and loadlib3 command paths were not fully implemented at the time of analysis. The proxy botnet is the current monetization model; the underlying access gives the operator considerably more capability than proxying traffic.”
John Strand, Owner, Black Hills Information Security, Inc.:
“If I’m looking at the overall trend of attacks we’ve been seeing lately, this fits right in. Supply chain attacks, malicious NPM packages, and similar techniques are increasingly showing up in some of the more advanced and interesting attacks. I’m not necessarily talking about ransomware here. I’m talking about attackers deliberately targeting areas that create blind spots for information security teams.
“For years, so much of information security has been focused on endpoints and EDR. More recently, organizations have started expanding that focus into cloud and identity security. That’s good, but attackers are moving into technologies that many traditional security stacks simply weren’t designed to monitor.
“Supply chain attacks are a perfect example. So is Android malware targeting head units used by automobile manufacturers. Most people aren’t running EDR on their car.
That sounds funny, but it highlights a serious problem.
“Attackers are finding technologies that fall outside the visibility of traditional security tools. Once they get into those environments, they have an opportunity to propagate, establish persistence, and potentially remain undetected for long periods of time. The problem isn’t necessarily that security teams aren’t paying attention. In many cases, the technology they’ve invested in simply doesn’t support these systems.”
Related
This entry was posted on August 24, 2026 at 6:25 pm and is filed under Commentary with tags Kaspersky. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Supply chain attack infects Android car systems with botnet malware
Kaspersky researchers uncovered a supply chain attack infecting Android-based car head units with malware designed for ad fraud and proxy botnet activity.
The malware was distributed through the built-in updater of TWCore, a legitimate system application installed on head units from Chinese automotive technology provider DoFun. Researchers said this is the first documented malware infection chain specifically designed to target automotive head units.
The attack uses a three-stage infection chain, beginning when the legitimate updater downloads a malicious APK. Once installed, additional malware components are retrieved that can generate fraudulent advertising activity and turn the vehicle’s internet connection into a proxy for other traffic.
The threat is imminent. Today’s notice of the critical Keycloak Password Reset Flaw (CVE-2026-18963, CVSS 9.1) exposes thousands of enterprise identity servers to risk of complete, unauthenticated takeover.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“MoYu Group, the same actor behind BADBOX infections on cheap Android TV set-top boxes, expanded to car dashboards because to a residential proxy operator, any Android device with a Subscriber Identity Module (SIM) card is just inventory.
“DoFun’s TWCore updater accepts instructions from a Message Queuing Telemetry Transport (MQTT) broker and includes a flag called installNotExists that lets the server push entirely new applications to the device without human approval. The attackers pushed malware through this privileged deployment channel exactly as it was designed to work.
“The zhima proxy module on these head units ties back to residential proxy services PXYEDGE and ProxyForU, both connected to MoYu Group’s broader infrastructure. Compromised vehicles are being sold as proxy endpoints to whoever pays. A car sitting in a parking lot becomes someone else’s exit node, routing traffic through a cellular connection the vehicle owner pays for.
“Every original equipment manufacturer (OEM) sourcing Android-based head units from third-party firmware providers should be asking who audited the update channel before it shipped. Arbitrary code delivery already works through loadlib2, while loadlib and loadlib3 command paths were not fully implemented at the time of analysis. The proxy botnet is the current monetization model; the underlying access gives the operator considerably more capability than proxying traffic.”
John Strand, Owner, Black Hills Information Security, Inc.:
“If I’m looking at the overall trend of attacks we’ve been seeing lately, this fits right in. Supply chain attacks, malicious NPM packages, and similar techniques are increasingly showing up in some of the more advanced and interesting attacks. I’m not necessarily talking about ransomware here. I’m talking about attackers deliberately targeting areas that create blind spots for information security teams.
“For years, so much of information security has been focused on endpoints and EDR. More recently, organizations have started expanding that focus into cloud and identity security. That’s good, but attackers are moving into technologies that many traditional security stacks simply weren’t designed to monitor.
“Supply chain attacks are a perfect example. So is Android malware targeting head units used by automobile manufacturers. Most people aren’t running EDR on their car.
That sounds funny, but it highlights a serious problem.
“Attackers are finding technologies that fall outside the visibility of traditional security tools. Once they get into those environments, they have an opportunity to propagate, establish persistence, and potentially remain undetected for long periods of time. The problem isn’t necessarily that security teams aren’t paying attention. In many cases, the technology they’ve invested in simply doesn’t support these systems.”
Share this:
Like this:
Related
This entry was posted on August 24, 2026 at 6:25 pm and is filed under Commentary with tags Kaspersky. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.