Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Malware Hijacks Android Car Infotainment Systems: A Growing Security Threat


Malware has been found to be hijacking Android car infotainment systems, turning them into nodes for the BADBOX botnet. This malicious software is using infected cars' internet connections as part of a larger proxy network, raising concerns about the potential for widespread exploitation.

  • Malware has been found hijacking Android car infotainment systems, turning them into nodes for the BADBOX botnet.
  • The malware, dubbed "Manic," is a multi-stage downloader that spreads through Android-based automotive head unit firmware updates.
  • The infection chain begins inside a legitimate system app responsible for analytics and firmware updates.
  • The malware sends POST requests to a command server every 90 minutes, containing information about the infected device.
  • The campaign is attributed to MoYu Group, an actor connected to the BADBOX botnet.
  • The discovery highlights the need for improved security protection in the automotive industry.
  • The use of Android in car infotainment systems creates a security risk, allowing malware to spread silently and unnoticed.



  • Malware Hijacks Android Car Infotainment Systems: A Growing Security Threat

    In a shocking discovery, researchers from Kaspersky have found a new type of malware that is hijacking Android car infotainment systems, turning them into nodes for the BADBOX botnet. This malicious software is abusing car infotainment updates to install proxy software, allowing the attackers to use infected cars' internet connections as part of a larger proxy network.

    The malware, which is dubbed "Manic," is a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet. It spreads through the built-in updaters of Android-based automotive head unit firmware, taking advantage of the fact that these systems are basically Android devices, which means many apps designed for smartphones can also run on them, including malware.

    The infection chain begins inside TWCore, a completely legitimate system app responsible for analytics and firmware updates on DoFun head units. An MQTT message broker sends TWCore instructions about which APK files to download and install, and a specific configuration flag called installNotExists controls whether the app checks if something is already installed before pushing it.

    When this flag is set to false, the malware installs a small dropper called JarService, carrying zero user interface and doing nothing but decrypting and loading the next stage. That stage is a loader that phones home to a command server, reports basic device details, and receives a download link for the actual payload, a third-stage module that researchers found could be pulled in at least seven different versions simply by trying different version numbers in the download URL.

    The third-stage module turns out to be a clicker and reverse proxy component, checking in with its server every 90 minutes by default and waiting for new instructions. This malware sends a POST request to /cpc/api/task every 90 minutes by default, containing information about the infected device, such as display resolution, device model, the SSID of the connected Wi-Fi network, MAC address, and so on.

    The command system behind the malware is more powerful than expected, with nine commands, including ones that can change the clipboard, send HTTP requests, load web pages, and run JavaScript. In practice, attackers mainly used two: one to download and run new code, and another to send web requests.

    Tracing the malware's naming conventions and infrastructure led researchers to attribute the campaign to MoYu Group, an actor connected to the BADBOX botnet that has been documented previously. This campaign shows why the people behind it keep changing how they spread the malware and are moving into new types of devices, including cars, smart TVs, and set-top boxes.

    The implications of this discovery are significant, as it highlights the need for improved security protection in the automotive industry, where cars are becoming more like computers. The use of Android in car infotainment systems, which are essentially Android devices under the hood, has created a security risk, allowing malware to spread silently and unnoticed.

    The fact that the malware is using infected cars' internet connections as part of a larger proxy network raises concerns about the potential for widespread exploitation. As cars become more connected to the internet, the risk of malware spreading to these devices increases, making it essential for manufacturers and regulators to take action to address this growing security threat.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Malware-Hijacks-Android-Car-Infotainment-Systems-A-Growing-Security-Threat-ehn.shtml

  • https://securityaffairs.com/197700/hacking/malware-hijacks-android-car-head-units.html


  • Published: Sat Aug 22 04:52:02 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us