Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Named Pipes Under Attack: Securing Windows Interprocess Communication

    August 22, 2026

    Solana governance vote nears amid 60% quorum display error

    August 22, 2026

    Fontainebleau forest near Paris reopens after devastating wildfire

    August 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Named Pipes Under Attack: Securing Windows Interprocess Communication
    • Solana governance vote nears amid 60% quorum display error
    • Fontainebleau forest near Paris reopens after devastating wildfire
    • Germany becomes Europe’s largest regulated cannabis market
    • Set Up a Separate Work Profile on Your Android Phone
    • Hackers infect Android car head units with proxy botnet malware
    • AI Has Made Bitcoin Software a Target—This Group Is Fighting Back
    • Exercise may work better for keeping weight off than losing it
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers infect Android car head units with proxy botnet malware

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 22, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud.

    Kaspersky researchers analyzed the malware and attributed the operation to the MoYu group, a threat actor previously associated with the BadBox malware botnet.

    The researchers note that this is the first documented case of a malware infection chain specifically created for the targeted car head unit.

    image

    MoYu’s operation targets systems from DoFun, a Chinese automotive software and hardware provider owned by Shenzhen Driving Control Technology Co., Ltd.

    DoFun is an automotive software, cloud services, and hardware provider that sells generic Android-based head units, which act as the command center for a car’s infotainment, navigation, and settings systems.

    In June, Kaspersky researchers found a rogue APK file being downloaded from a legitimate DoFun system app, TWCore, which receives instructions through an MQTT server hosted at cardoor[.]cn.

    The unknown app has no interface and is a piece of malware called JarService. When launched, the malware decrypts and executes a second-stage loader that establishes communication with a command-and-control (C2) server and downloads another encrypted payload.

    The final payload periodically reports device information such as the model, display resolution, Wi-Fi SSID, and MAC address, and retrieves commands from the attackers.

    The malware supports the following nine commands:

    1. return – Retrieves a specified value from Android’s SharedPreferences storage
    2. copy – Copies stored or downloaded content to the device clipboard
    3. http – Sends HTTP GET or POST requests and can save part of the response
    4. web – Opens a URL in a WebView and executes supplied JavaScript
    5. loadlib – Not fully implemented when Kaspersky published the report
    6. loadlib2 – Downloads and executes arbitrary code or additional modules
    7. loadlib3 – Not fully implemented when Kaspersky published the report
    8. deeplink – Opens a specified resource in the browser
    9. traceroute – Checks whether specified hosts are reachable using ICMP ping

    Kaspersky says the malware does not interfere with driving or critical vehicle control systems, and appears designed for advertising fraud and turning internet-connected car head units into residential proxy nodes for monetization purposes.

    The head unit infection scheme
    The head unit infection scheme
    Source: Kaspersky

    Researchers discovered that the operator primarily loaded a reverse-proxy module named ‘zhima,’ which turns the head unit into a proxy botnet node, and also made web requests for click-fraud activity.

    Kaspersky says it notified DoFun of its findings, and the Chinese firm replied that it resolved the problem.

    BleepingComputer has contacted both companies with questions about the initial compromise vector, and we will update the article with the information once received.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Android Botnet car hackers infect Malware Proxy units
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Named Pipes Under Attack: Securing Windows Interprocess Communication

    Set Up a Separate Work Profile on Your Android Phone

    Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

    Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

    Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

    CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Named Pipes Under Attack: Securing Windows Interprocess Communication

    August 22, 2026

    Solana governance vote nears amid 60% quorum display error

    August 22, 2026

    Fontainebleau forest near Paris reopens after devastating wildfire

    August 22, 2026

    Germany becomes Europe’s largest regulated cannabis market

    August 22, 2026
    Latest Posts

    Satirical fake Guardian front page on ‘genetic links’ between eating bacon and far-right activism shared as genuine – Full Fact

    July 28, 2026

    U.S. Foreign Policy Must Prioritize Human Rights

    July 28, 2026

    Madison revisits police body cameras after years of debate

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Named Pipes Under Attack: Securing Windows Interprocess Communication

    August 22, 2026

    Solana governance vote nears amid 60% quorum display error

    August 22, 2026

    Fontainebleau forest near Paris reopens after devastating wildfire

    August 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.