Researchers have identified new Android malware targeting automotive head units, which exploits legitimate firmware update mechanisms to install a multi-stage downloader for ad fraud and proxy botnet operations.
Key Points
- The malware, attributed to the MoYu Group, is the first documented instance of malicious software specifically infecting Android-based automotive head units.
- Attackers leveraged the "TWCore" system application, which manages analytics and software updates, to silently download and install the malicious payload without user interaction.
- The infection chain consists of three stages: a UI-less dropper, a loader that fetches additional code, and a final module that executes ad fraud and proxy tasks.
- The final stage, known as the "zhima" module, turns the infected head unit into a node for a residential proxy botnet.
- Security researchers confirmed the vendor of the affected DoFun head units has since patched the vulnerability used for the unauthorized app distribution.