<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/first-android-malware-targeting-automotive-head-units-a8fvs7dcl" -->

---
title: First Android malware targeting automotive head units
description: Kaspersky researchers discovered a new multi-stage Android malware family delivered through the legitimate update mechanism of TWCore, a system app used on...
canonical: https://daily.dev/posts/first-android-malware-targeting-automotive-head-units-a8fvs7dcl
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: First Android malware targeting automotive head units | daily.dev
og:description: Kaspersky researchers discovered a new multi-stage Android malware family delivered through the legitimate update mechanism of TWCore, a system app used on...
og:url: https://daily.dev/posts/first-android-malware-targeting-automotive-head-units-a8fvs7dcl
og:image: https://api.daily.dev/og/posts/a8FVs7dCL.png
og:image:alt: First Android malware targeting automotive head units
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# First Android malware targeting automotive head units

**[Securelist](https://daily.dev/sources/securelist)** · 13 min read · 0 upvotes · 0 comments

## Summary

Kaspersky researchers discovered a new multi-stage Android malware family delivered through the legitimate update mechanism of TWCore, a system app used on DoFun-made automotive head units. The infection chain begins with a JarService dropper, followed by a loader, and finally a clicker/reverse-proxy payload named zhima that builds a proxy botnet and commits ad fraud. This marks the first documented malware infection chain specifically targeting car head units. Kaspersky attributes the campaign with high confidence to MoYu Group, an actor linked to the BADBOX botnet, based on code naming overlaps and shared infrastructure with malware also found on TV set-top boxes. The vendor was notified and reportedly fixed the distribution issue. Indicators of compromise including file hashes, C2 domains, and IPs are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securelist.com/android-head-unit-malware/121106>

## Questions this post answers

### How did malware get installed on Android-based car head units?

Attackers abused the built-in update function of TWCore, a legitimate system app on DoFun head units responsible for analytics and software updates. An MQTT message broker on the subdomain cardoor.cn sent messages with an installNotExists flag set to true, letting TWCore silently install a dropper called JarService that was never originally present on the device.

_Teams securing connected vehicle software track supply-chain abuse cases like this via daily.dev._

### What is the zhima Android malware module and what does it do?

Zhima is a reverse proxy module downloaded via the loadlib2 command in a multi-stage Android infection chain, turning infected devices into nodes in a proxy botnet. It was independently found by Nokia Deepfield researchers on TV set-top boxes around the same time, confirming the attackers' goal of monetizing device network access through residential proxy services like PXYEDGE and ProxyForU.

_Anyone tracking proxy botnet infrastructure and IoT malware trends can follow research like this on daily.dev._

### Who is behind the BADBOX-linked head unit malware attack?

Kaspersky attributes the campaign with high confidence to MoYu Group, an actor linked to the BADBOX botnet. Attribution rests on a malicious thread named mosdk-host-loader, a related app on TV set-top boxes with a service called AdmoyuService, and infrastructure overlap independently confirmed by Nokia Deepfield researchers around the same period.

_Security teams mapping botnet actor infrastructure can follow attribution research like this on daily.dev._

## Similar posts on daily.dev

- [A vehicle's head unit hacked via its modem](https://daily.dev/posts/a-vehicle-s-head-unit-hacked-via-its-modem-hlvyfve1z) · Securelist · 1 upvotes · 0 comments
- [Kimwolf v7: An Evolution of the Kimwolf Botnet](https://daily.dev/posts/kimwolf-v7-an-evolution-of-the-kimwolf-botnet-qyisegkoc) · Unit 42 · 0 upvotes · 0 comments
- [Android Trojan 'Fantasy Hub' Malware Service Turns Telegram Into a Hub for Hackers](https://daily.dev/posts/android-trojan-fantasy-hub-malware-service-turns-telegram-into-a-hub-for-hackers-kdredzisd) · The Hacker News · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/first-android-malware-targeting-automotive-head-units-a8fvs7dcl)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"First Android malware targeting automotive head units","url":"https://daily.dev/posts/first-android-malware-targeting-automotive-head-units-a8fvs7dcl","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/first-android-malware-targeting-automotive-head-units-a8fvs7dcl"},"datePublished":"2026-08-21T08:03:45.849Z","dateModified":"2026-08-26T18:41:48.658Z","description":"Kaspersky researchers discovered a new multi-stage Android malware family delivered through the legitimate update mechanism of TWCore, a system app used on...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/33363e85d28918e23a9c27629e812c42?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/33363e85d28918e23a9c27629e812c42?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Securelist","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Securelist","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/e4b9f556af7a4e74a179787362dd5b07","url":"https://daily.dev/sources/securelist"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/first-android-malware-targeting-automotive-head-units-a8fvs7dcl","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,malware","timeRequired":"PT13M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Securelist","item":"https://daily.dev/sources/securelist"},{"@type":"ListItem","position":3,"name":"First Android malware targeting automotive head units"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/first-android-malware-targeting-automotive-head-units-a8fvs7dcl#faq","mainEntity":[{"@type":"Question","name":"How did malware get installed on Android-based car head units?","acceptedAnswer":{"@type":"Answer","text":"Attackers abused the built-in update function of TWCore, a legitimate system app on DoFun head units responsible for analytics and software updates. An MQTT message broker on the subdomain cardoor.cn sent messages with an installNotExists flag set to true, letting TWCore silently install a dropper called JarService that was never originally present on the device. Teams securing connected vehicle software track supply-chain abuse cases like this via daily.dev."}},{"@type":"Question","name":"What is the zhima Android malware module and what does it do?","acceptedAnswer":{"@type":"Answer","text":"Zhima is a reverse proxy module downloaded via the loadlib2 command in a multi-stage Android infection chain, turning infected devices into nodes in a proxy botnet. It was independently found by Nokia Deepfield researchers on TV set-top boxes around the same time, confirming the attackers' goal of monetizing device network access through residential proxy services like PXYEDGE and ProxyForU. Anyone tracking proxy botnet infrastructure and IoT malware trends can follow research like this on daily.dev."}},{"@type":"Question","name":"Who is behind the BADBOX-linked head unit malware attack?","acceptedAnswer":{"@type":"Answer","text":"Kaspersky attributes the campaign with high confidence to MoYu Group, an actor linked to the BADBOX botnet. Attribution rests on a malicious thread named mosdk-host-loader, a related app on TV set-top boxes with a service called AdmoyuService, and infrastructure overlap independently confirmed by Nokia Deepfield researchers around the same period. Security teams mapping botnet actor infrastructure can follow attribution research like this on daily.dev."}}]}
```

