Published: August 2026
What Happened
In June 2026, Kaspersky's Securelist team discovered a new piece of Android malware targeting automotive head unit firmware. What made this discovery unusual was that the malware installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. This led researchers to suspect the app might be reaching devices without the user's knowledge.
Further investigation confirmed the hypothesis and allowed the team to reconstruct the entire infection chain. The malware spread through the built-in updaters of Android-based automotive head unit firmware -- the first documented case of malware found on a car head unit with an infection chain specific to that type of device.
Attack Vector & Initial Access
The attack began with a legitimate system application called TWCore, responsible for collecting analytics data and updating head unit software. The TWCore app runs on a subdomain cardoor[.]cn via an MQTT message broker. The broker sends messages containing information about APK files that need to be downloaded and installed on the head unit.
A key feature of the TWCore update function is an installNotExists field -- a Boolean flag that can be set to true or false. When set to true, this flag allows TWCore to install apps that weren't originally present on the device. Attackers exploited this mechanism to distribute malware.
The malware payload, dubbed JarService, is a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet. The infection chain involves:
- TWCore app (legitimate system app used as a delivery mechanism)
- MQTT broker on
cardoor[.]cn(command and control infrastructure) - JarService (multi-stage downloader/ad fraud malware)
- Proxy botnet (recruited head units)
Infrastructure & Tooling
The malware operators used several domain names for their C2 infrastructure:
xmsae[.]sbsishano456[.]sbsxshaon123[.]sbskshahnd[.]sbsmdsjhd[.]sbsnmnsny[.]sbskookjar[.]comty54fgd435[.]myue886578433[.]onlinety4523[.]space
And IP addresses including:
144.217.243.201107.151.248.132128.14.210.58
The malware also used specific domains to download the JarService APK:
hxxp://ovcloudcontrol.cdn.cardoor[.]cn/upgrade/2026-06-08/bd80bd3c3d0e4bf6b5b4a825650d01f5.apkhxxp://ovcloudcontrol.cdn.cardoor[.]cn/upgrade/2025-06-10/fe71af9ecf174de48d2b2ccc2c15fb04.apkhxxp://ovcloudcontrol.cdn.cardoor[.]cn/upgrade/2024-11-07/fa831c3c23824b99871163387bcda7ad.apk
Attribution & Threat Actor Profile
Kaspersky attributes this activity with high confidence to the MoYu Group, an actor linked to the BADBOX botnet. BADBOX is a well-known botnet that primarily targets Android devices embedded in IoT products, particularly automotive head units and Android TV boxes.
The MoYu Group has been active in distributing malware through legitimate-looking system applications. By exploiting the TWCore update mechanism, they were able to bypass typical security controls and infect a large number of devices.
Targeting & Victimology
The primary victims are owners of vehicles with Android-based infotainment head units. These systems are found in cars from various manufacturers, particularly those using DoFun head unit firmware. The malware doesn't directly target the vehicle's driving functions, but the implications are significant:
- Privacy concerns: Infected head units can be recruited into botnets, potentially exposing location data and usage patterns
- Security risks: The proxy botnet infrastructure can be used for further attacks
- Device integrity: Compromised head units may have altered software integrity
Mitigation & Detection
Kaspersky solutions detect the threats described under the following detection names:
HEUR:Trojan-Dropper.AndroidOS.Agent.vuHEUR:Trojan-Downloader.AndroidOS.Agent.ovHEUR:Trojan-Proxy.AndroidOS.Zhima.*HEUR:Trojan.AndroidOS.Vo1d.*
Recommended mitigations for vehicle owners:
- Keep head unit firmware updated: Apply security updates from the vehicle manufacturer
- Disable unnecessary connectivity: Turn off Wi-Fi and other wireless features when not in use
- Monitor for unusual behavior: Watch for unexpected battery drain, data usage, or system performance issues
- Contact manufacturers: Report any security concerns to vehicle manufacturers
Detection rules for security teams:
Sigma rule example for detecting TWCore abuse:
IOCs (Indicators of Compromise):
- Domains:
xmsae[.]sbs,ishano456[.]sbs,xshaon123[.]sbs,kshahnd[.]sbs,mdsjhd[.]sbs,nmnsny[.]sbs,kookjar[.]com,ty54fgd435[.]my,ue886578433[.]online,ty4523[.]space - IPs:
144.217.243.201,107.151.248.132,128.14.210.58 - APK hashes:
2a64c3efc11bf224aa54f24e876446c9,7a4d3ba2dacccfdda55859a5dfee2671,ea24487996eb70c1780922fb3063bcc5
Frequently Asked Questions
Q: Can this malware affect my car's driving functions? A: No, the malware targets the head unit's Android-based operating system and does not have access to the vehicle's critical driving systems. However, compromised infotainment systems could potentially be used as an entry point for other attacks.
Q: Should I be concerned if I don't have a connected car? A: If you don't have an Android-based head unit, you are not at risk from this specific malware. However, the techniques used could potentially be adapted for other types of embedded systems.
Q: How can I check if my head unit is infected? A: Look for signs such as unexpected data usage, rapid battery drain on connected smartphones, or unusual system behavior in the head unit interface. Kaspersky's security products can detect the threats based on the IOCs listed above.
Q: What is BADBOX and how does it relate to this malware? A: BADBOX is a botnet primarily targeting Android devices embedded in IoT products, particularly automotive head units and Android TV boxes. The MoYu Group, attributed to this campaign, has been active in distributing malware through legitimate-looking system applications like TWCore.
Q: Will updating my head unit firmware remove the malware? A: Applying security updates from the vehicle manufacturer should prevent infection by patching the TWCore vulnerability. If already infected, a factory reset or firmware flash may be required, following the manufacturer's guidelines.
Key Takeaways
- Android malware targeting automotive head unit firmware is a emerging threat vector
- The TWCore update mechanism was exploited to distribute malware through legitimate-looking over-the-air updates
- The attack is attributed to the MoYu Group, linked to the BADBOX botnet
- Infected devices are recruited into a proxy botnet for ad fraud
- Vehicle owners should keep firmware updated and monitor for unusual behavior
- Security researchers have provided IOCs and Sigma detection rules for detection
Sources
- Kaspersky Securelist: The invisible passenger in your car
- Kaspersky: TWCore malware analysis
- Patch the Planet initiative
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.