Cybersecurity

Supply Chain Attack Turns Car Infotainment Units into Proxy Network Nodes

The MoYu group used a legitimate update application belonging to a Chinese provider for Android-based head units and deployed the JarService malware, which exploits the devices in a proxy network and for advertising fraud. Kaspersky says DoFun fixed the issue after being notified, while the initial compromise mechanism remains unclear.

2026-08-22
3 min read
13 views
فريق تحرير certi.news
Supply Chain Attack Turns Car Infotainment Units into Proxy Network Nodes

Kaspersky researchers discovered an infection chain targeting Android-based head units in cars and abusing a legitimate update application to distribute malware. According to the analysis, infected devices join a network of proxy nodes that can be rented out or used to generate financial returns, and they are also exploited to carry out advertising fraud.

The researchers attributed the operation to the MoYu group, a threat actor previously linked to the BadBox malware network. They say this is the first documented infection chain specifically designed to target car head units, the devices that typically manage infotainment, navigation, and vehicle settings.

How Did the Infection Begin?

The operation targets systems supplied by DoFun, a Chinese company that provides software, cloud services, and hardware components for cars, and sells generic Android-based head units. In June, Kaspersky researchers identified a malicious APK being downloaded from the TWCore application, a legitimate system app within the DoFun ecosystem that is intended to receive device updates.

TWCore received instructions through an MQTT server hosted on the cardoor[.]cn domain. The concealed app is named JarService and provides no user interface. When launched, it decrypts and executes a second-stage loader, then establishes a connection to a command-and-control server to download another encrypted payload.

The final payload collects information about the device, including its model, screen resolution, Wi-Fi network name, and MAC address, then receives commands from the operators. The functions documented by the researchers include:

  • Reading specific values from SharedPreferences storage.
  • Copying stored or downloaded content to the clipboard.
  • Sending HTTP GET or POST requests and saving parts of the response.
  • Opening URLs inside a WebView and executing JavaScript specified by the attackers.
  • Downloading and executing additional code or modules through the loadlib2 function, with two other functions remaining incomplete.
  • Opening specific resources in a browser and checking whether hosts are reachable through ICMP ping.

What Does the Infected Device Do?

Kaspersky observed the loading of a reverse-proxy module named zhima, which turns the head unit into a node within a proxy network. The researchers also observed web requests associated with click-fraud activity. According to the published findings, the malware does not interfere with driving or the vehicle’s critical control systems, and its primary goal appears to be monetizing the device’s internet connection rather than directly controlling the vehicle.

Why Does This Matter?

The incident is significant because it extends the botnet model to a component located inside a vehicle while relying on a legitimate system application during distribution. This broadens the scope of supply-chain risks from phones and Internet of Things devices to connected-car platforms, even when the threat is not related to driving control.

Kaspersky notified DoFun of the findings, and the Chinese company said it had fixed the issue. However, the initial compromise mechanism, including how the malicious file entered the update ecosystem, has not been established in the available material. BleepingComputer also said it requested additional information from both companies and will update its report upon receiving it.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news