Hackers have found a new way into connected cars by turning trusted Android updates into a malware delivery route | Tech Radar
Overview
News, deals, reviews, guides and more on the newest computing gadgets
Start exploring exclusive deals, expert advice and more
Details
Unlock and manage exclusive Techradar member rewards.
Unlock instant access to exclusive member features.
Get full access to premium articles, exclusive features and a growing list of member rewards.
Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Hackers exploited trusted software updates to deliver malware directly into car head units
Kaspersky says this is the first campaign tailored specifically for vehicle head units
The malware can run silently without showing drivers any visible interface
Car head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.
A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.
According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.
Compromised update channels deliver malware straight into vehicles
Researchers believe the activity can likely be traced back to the Mo Yu Group, a threat actor closely tied to the well-known Bad Box botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by Do Fun.
The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.
Experts warn hackers are hiding malware inside Google's own ad systems — here's what we know
Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth
Experts warn Claude feature hijacked by hackers to launch major malware campaign
Attackers hijacked this trusted update channel using a specialized dropper called Jar Service to deliver previously unknown malware directly onto a range of affected devices.
Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.
Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.
The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device's MAC address.
Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.
Hackers are hijacking legitimate news websites and reviews to drum up publicity
Geekom reveals multiple mini-PCs may be infected with malware hidden in a network driver — but it's now down to you to fix your PC
Thousands of compromised websites abused by Drive Surge in active Click Fix and Fake Updates campaigns
The research team claims that the botnet's administration panel shares embedded URLs with residential proxy service websites PXYEDGE and Proxy For U.
Bad Box itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.
Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.
According to statements from Do Fun, the underlying issue has since been resolved across most affected devices currently deployed in the field.
Head units present a growing and largely unprotected attack surface
Car head units can arrive factory-installed directly from the manufacturer or get added later to older vehicles as aftermarket upgrades.
Manufacturers frequently rely heavily on the Android operating system because it simplifies interface customization and essential system integration work considerably.
This widespread industry reliance means most standard Android applications, along with most existing Android malware, can potentially run on these devices.
Head units rarely store sensitive personal data directly on board, which on the surface might suggest only limited appeal to attackers.
However, they typically include active SIM card slots and maintain constant internet connectivity for navigation services and routine software updates.
That particular combination of persistent connectivity and comparatively weak security oversight makes these systems a genuinely attractive prospect for attackers going forward.
The overall scale of this particular campaign remains genuinely unclear, and whether other head unit manufacturers face similar exposure is not yet known.
Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master's and a Ph D in sciences, which provided him with a solid foundation in analytical thinking.
You must confirm your public display name before commenting
I'll be watching The Real Housewives of Beverly Hills for the first time ever thanks to the season 16 trip to Ghana — Bozoma Saint John's wedding just changed the game
I'm a homes and gardens expert — here are 12 backyard bargains I'd pick up in the Walmart early Labor Day sale
Sorry Garmin — forget the Fenix 9, this Casio G-Shock pro surfer collab is the only new adventure watch I want this year
New malware targets Microsoft Teams users by posing as your company's IT helpdesk
Want a cheap i Phone on a cheap plan? This deal at Metro by T-Mobile gets you a device included without having to trade
Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.
Key Takeaways
- News, deals, reviews, guides and more on the newest computing gadgets
- Start exploring exclusive deals, expert advice and more
- Unlock and manage exclusive Techradar member rewards
- Unlock instant access to exclusive member features
- Get full access to premium articles, exclusive features and a growing list of member rewards



