Code Defence Cyber security

MoYu Group infects Android car head units to build proxy botnet via update daemon manipulation

Cyber threat research disclosures have exposed a novel malware campaign weaponizing built-in software update pathways on Android-based vehicle infotainment systems. The operation bypasses standard application store lures to quietly turn connected automotive screens into reverse proxy nodes.

The attack chain targets automotive head units running analytics software package TWCore. Threat actors associated with the MoYu Group transmitted manipulated update instructions over MQTT infrastructure, abusing an installNotExists setting to force TWCore to download and install a silent background package named JarService. Once deployed, JarService fetches a secondary reverse-proxy module called zhima, routing external internet traffic through the vehicle cellular or Wi-Fi connection without user interaction or visual display indicators.

Subverting automotive infotainment hardware introduces novel network proxy and privacy risks. While the campaign has not been observed interfering with safety-critical driving controllers, converting connected vehicle head units into proxy nodes allows threat networks to mask malicious cybercrime traffic behind legitimate consumer connection origins.

– Apply firmware updates provided by automotive hardware vendors to restrict background software installation paths.

– Enforce strict digital signature verification on all remote package updates distributed by internal telemetry daemons.

– Monitor cellular and Wi-Fi transit traffic originating from connected vehicle hardware for anomalous proxy communication streams.

– Restrict administrative permissions on internal update caches to prevent unauthorized binary dropping.

Automotive edge security relies on cryptographically signed update channels and strict component isolation to guarantee connected vehicle dashboards cannot be subverted into unmonitored proxy infrastructure. #CodeDefence #AutomotiveSecurity #AndroidMalware #ProxyBotnet #Kaspersky #MoYuGroup #IoTSecurity #AppSec
/

Scroll to Top