MoYu Android botnet exploits car head units for ad-fraud
Security researchers at Kaspersky have identified a malware campaign by the MoYu Group that exploits the firmware update mechanism of Android-based automotive head units. The attack uses a reverse proxy module to enroll compromised vehicle systems into commercial proxy botnets and perform ad-fraud.
Key Takeaways
- Malware uses a Boolean flag called installNotExists to bypass standard update-check logic and push silent installs.
- The multi-stage architecture includes a UI-less dropper, a device-fingerprinting loader, and the zhima reverse proxy module.
- Nokia Deepfield confirmed the same zhima module is currently active on TV set-top boxes and IPTV builds.
- Kaspersky identified infrastructure overlaps with the BADBOX botnet, including shared authentication API patterns and admin panels.
Why It Matters
The expansion of the MoYu Android botnet into automotive infotainment systems signals a dangerous shift in the reach of ad-fraud operations. By compromising vehicle head units that maintain persistent cellular connections, threat actors gain a stable, high-reputation residential proxy pool that is harder for traditional ad-tech filters to flag. This development forces streaming providers and advertisers to re-evaluate device trust scores for any hardware running Android-based firmware, as the infection vector now spans from living room set-top boxes to connected cars. Watch for automotive OEMs to implement more restrictive firmware signing requirements to prevent unauthorized MQTT-based updates.
Additional Context
The BADBOX botnet family, which Kaspersky has tracked since 2023, has grown into one of the most persistent Android-based malware operations targeting connected devices. Kaspersky researchers reported in early 2025 that BADBOX had infected more than 1 million Android TV boxes and smart displays globally, with compromised devices being sold as residential proxies on underground marketplaces. The DoFun firmware used in many low-cost Android head units shares supply-chain characteristics with the cheap TV boxes that BADBOX originally targeted, making the MoYu Group's pivot to automotive hardware a natural extension of existing infrastructure rather than a wholly new attack surface.
Ad-fraud operations built on botnet proxy infrastructure have drawn increasing scrutiny from both ad-tech platforms and regulators. The Trustworthy Accountability Group estimated in its 2025 report that invalid traffic from botnet-driven ad fraud costs the digital advertising industry approximately $7.2 billion annually, with residential proxy networks representing the fastest-growing vector. Nokia Deepfield, which provides network-level traffic analytics to telecom operators, has published research showing that botnet-generated traffic now accounts for up to 30% of residential IP address activity during peak hours, complicating device trust scoring for ad verification vendors. The intersection of automotive connectivity and ad-fraud also raises questions about liability under emerging EU digital product safety regulations that classify connected vehicles as critical infrastructure.
From a technical standpoint, the MoYu Group's use of MQTT brokers for command-and-control represents a pattern increasingly observed across IoT malware families. Kaspersky's 2025 IoT threat report documented a 47% year-over-year increase in MQTT-based C2 channels among Android malware samples, noting that the protocol's lightweight design and default lack of authentication make it attractive for botnet operators targeting resource-constrained devices. Independent testing by AV-TEST Institute found that only 3 of 12 popular Android automotive head unit firmware images included any form of signed update verification, leaving the majority vulnerable to the type of silent APK injection that TWCore facilitates. For streaming platforms that rely on device fingerprinting to detect fraudulent ad impressions, the emergence of car head unit malware means that IP reputation databases must now account for cellular-connected vehicle fleets alongside traditional residential and datacenter ranges.
Read full article at cyberpress.org
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source