A recent discovery has revealed a new Android malware campaign targeting car infotainment systems. Instead of using deceptive apps, hackers exploit the built-in software update mechanism of Android-based head units to deploy their malicious software.
Exploiting Android Updates
The malware serves as a multi-stage downloader designed for ad fraud and proxy botnet activities. It leverages the connectivity of vehicle screens, which manage functions like music and navigation, by infiltrating the usual internet-based software update process. This turns a trusted feature into an entry point for extensive criminal operations. The security firm Securelist identified the malware in June 2026, linking it to the MoYu Group, associated with BADBOX.
Securelist’s report, shared with Cyber Security News, highlights how the malware exploits firmware design to spread. Despite vendor claims of addressing these vulnerabilities, this threat broadens concerns to include connected vehicle screens, beyond just phones and TVs.
Mechanisms of the Attack
The attack focuses on TWCore, a legitimate system app responsible for analytics and software updates. The attackers use an MQTT broker on cardoor[.]cn to send APK file details for download, enabling the installation of unauthorized apps. The malware lodges itself in the update cache, installed via the com.tw.core package.
The first component, JarService, operates without a user interface, decrypting data to initiate subsequent payloads discreetly. A second-stage loader reports device information to a remote server, receiving further instructions. The third stage collects device specifics, such as model and network details, updating its configuration as commanded.
Implications and Recommendations
This malware chain diverges from typical phone scams by bypassing fake texts or app store lures. Previous BADBOX infections have shown how compromised firmware can expose devices, but this new case brings the risk into vehicles, potentially compromising privacy and trust.
The final payload can display ads, perform click fraud, and fetch additional code, integrating the car screen into a hidden network. Researchers attribute this operation to MoYu Group, noting similarities with previous campaigns and linking it to a malicious TV-box app.
While the malware does not directly control critical vehicle functions like steering or braking, it poses significant privacy and connectivity risks. Owners are advised to install updates only from verified sources and inquire about security patches for their head units. Manufacturers should enforce signed updates and verify all remote instructions to maintain secure systems.
Overall, this incident underscores the necessity for vigilance in protecting connected vehicle systems from emerging threats.
