Ethical Hacking News
A new malware family has been discovered that specifically targets Android-based vehicle head unit firmware, exploiting the built-in updater to spread ad fraud and proxy botnet operations. The malware, dubbed JarService, has become the first malicious application specifically targeting car head units through an infection chain explicitly tailored for these vehicle systems. This highlights the urgent need for robust protection against malware in modern automotive platforms.
The Android-based vehicle head unit firmware has been compromised by a new malware family. The malware aims to serve a multi-stage downloader for ad fraud and proxy botnet creation. The malware spread through a critical vulnerability in the built-in updaters. The attack chain ends with the deployment of the malware as a covertly operating background application. The malware supports nine commands, including ad fraud and device information collection. The threat actors have been linked to the BADBOX botnet and its associated ad fraud scheme.
The Android-based vehicle head unit firmware developed by DoFun has recently been compromised by a new malware family specifically designed to infect these systems. According to Kaspersky, a leading cybersecurity research firm, the end goal of this malware is to serve a multi-stage downloader that enables ad fraud and the creation of a proxy botnet.
The malware spread through the built-in updaters of Android-based automotive head unit firmware, a critical vulnerability that allows the threat actors to deliver previously unknown malware directly to the head units using a dropper dubbed JarService. This dropper is responsible for launching a loader that performs a series of actions, including sending implant information to one of the attackers' servers via an HTTP POST request, and server responses with a link for downloading the next-stage payload.
The attack chain ends with the deployment of the malware as a regular user application, a covertly operating background application that lacks a user interface. The malware is configured to send a POST request to the command-and-control (C2) endpoint every 90 minutes, along with information about the infected device and its configuration version. If the configuration is outdated, the C2 server returns an updated configuration containing new C2 addresses and new paths for sending HTTP requests.
The malware supports nine commands capable of displaying unwanted advertisements, executing ad fraud, and downloading additional malicious modules. It also allows attackers to receive extensive device information, including display resolution, device model, connected Wi-Fi network identifier, and MAC address. The list of commands includes return, copy, http, web, loadlib, loadlib2, deeplink, traceroute, and more.
In this researched case, the malware has become the first malicious application specifically targeting car head units through an infection chain explicitly tailored for these vehicle systems. This serves as a warning that modern automotive platforms urgently require robust protection against malware.
The threat actors have been found to leverage "loadlib2" and "http" commands to download a reverse proxy module documented by Nokia Deepfield Emergency Response Team last month and selectively delivered via IPTV apps installed in cheap Android TV boxes. Despite the efforts of cybersecurity experts and law enforcement agencies to shut down the BADBOX botnet, individual actors associated with it continue their malicious activities, infecting devices worldwide.
The MoYu Group, which was outed by the HUMAN Satori Threat Intelligence and Research team last year as part of a broader ad fraud and residential proxy scheme dubbed BADBOX, is attributed with high confidence for the malware activity. Google filed a lawsuit against 25 unnamed individuals or entities in China for allegedly operating the BADBOX botnet and its infrastructure in July 2025.
Related Information:
https://www.ethicalhackingnews.com/articles/Android-Car-Malware-Spreads-Through-Built-In-Updaters-Exploits-Sim-Card-Slot-for-Ad-Fraud-and-Proxy-Botnet-Operations-ehn.shtml
https://thehackernews.com/2026/08/android-car-malware-spreads-through.html
Published: Fri Aug 21 12:46:06 2026 by llama3.2 3B Q4_K_M