Hackers are now targeting the head units of connected cars, exploiting trusted software update channels to install malware. Security researchers have identified a new campaign that specifically targets these in-car systems, which often combine multimedia functions with vehicle controls. This marks the first documented instance of malware designed with this particular infection chain in mind.
Malware Hijacks Vehicle Update Systems
The sophisticated attack campaign is believed to be orchestrated by the MoYu Group, a threat actor associated with the BadBox botnet. Researchers found that the attackers compromised the legitimate update mechanisms built into the firmware of Android-based head units manufactured by DoFun. These head units typically use a system app called TWCore, responsible for collecting analytics and managing remote software updates.
By hijacking this trusted update channel, attackers deployed a specialized tool known as JarService. This tool acted as a dropper, silently installing previously unknown malware onto the affected devices. Once embedded, the malware operates discreetly in the background, without any visible interface to alert the driver.
Malware Capabilities and Data Collection
The discovered malware is equipped with at least nine distinct remote commands. These capabilities allow attackers to display unwanted advertisements and engage in various forms of ad fraud. Beyond ad-related activities, the malware actively gathers sensitive device information. This includes details such as the screen resolution, the specific device model, Wi-Fi network identifiers, and the device’s MAC address.
Investigators noted clear technical similarities between this campaign and previous attacks targeting TV set-top boxes, which are also linked to the same broader threat group. The administration panel used for managing the botnet reportedly shares embedded URLs with residential proxy services, including PXYEDGE and ProxyForU. The BadBox botnet itself is known to operate as a vast network of compromised Android devices, encompassing streaming boxes, smartphones, and tablets that may arrive pre-infected from the factory.
Security firm Kaspersky, which identified the campaign, has officially informed the affected vendor about the misuse of their legitimate software distribution and update infrastructure. According to statements from DoFun, the underlying security vulnerability has since been addressed for the majority of deployed devices.
Connected Car Head Units: An Emerging Attack Surface
Car head units represent a growing and often under-protected area for cyber threats. These systems can be factory-installed by manufacturers or added to older vehicles as aftermarket upgrades. The widespread adoption of the Android operating system by manufacturers simplifies interface customization and system integration, making it a popular choice.
However, this reliance on Android means that many standard Android applications, and consequently, Android malware, can potentially run on these in-car systems. While head units might not typically store significant amounts of sensitive personal data directly, their connectivity features present a compelling target for attackers.
Many head units feature active SIM card slots and maintain constant internet connectivity for navigation services, streaming media, and software updates. This persistent online connection, combined with what is often comparatively weaker security oversight than found in consumer electronics, makes these systems an attractive prospect for malicious actors.
Implications for Vehicle Security
The full scope of this particular malware campaign remains unclear. It is also unknown whether other head unit manufacturers are facing similar security exposures. The ability to hijack these systems could potentially lead to a range of malicious activities, from disruptive ad bombardment to more serious forms of system manipulation, depending on the specific controls integrated into the head unit.
As vehicles become increasingly integrated with digital technologies, the security of their internal systems, including the head unit, becomes paramount. The recent discovery underscores the need for continuous vigilance and robust security measures to protect connected vehicles from evolving cyber threats.
Protecting Against In-Car Malware
While direct user intervention is limited once malware is installed via a compromised update, several preventative measures can be considered:
- Manufacturer Vigilance: Vehicle manufacturers and head unit suppliers must prioritize secure development practices and rigorous testing of their software and update mechanisms.
- Secure Update Channels: Ensuring that software updates are delivered through encrypted and authenticated channels is crucial to prevent tampering.
- Regular Security Audits: Independent security audits of in-car systems can help identify and address vulnerabilities before they are exploited.
- User Awareness: While not always feasible for sophisticated attacks, users should be cautious about aftermarket installations and ensure their vehicle’s software is kept up-to-date through official channels.
The ongoing evolution of cyber threats targeting connected vehicles highlights the critical importance of cybersecurity in the automotive industry. As these systems become more complex and interconnected, a proactive and multi-layered security approach is essential to safeguard drivers and their vehicles.


