MoYu Group Android head unit malware builds proxy botnet via firmware
Researchers have identified a malware campaign by the MoYu Group that exploits the TWCore system application in Android-based automotive head units to build a residential proxy botnet. The attack uses firmware update mechanisms to silently install malicious APKs, mirroring similar threats previously observed on Android-based TV set-top boxes.
Key Takeaways
- Attackers abused the TWCore privileged system application on DoFun-powered devices to bypass user installation prompts.
- The multi-stage infection chain deploys a headless application named JarService to decrypt and load the zhima proxy module.
- Compromised head units poll command-and-control servers every 90 minutes to report device metadata and receive new execution tasks.
- Nokia Deepfield researchers confirmed the same zhima component is currently active on infected TV set-top boxes.
Why It Matters
This campaign signals a strategic shift for botnet operators who are moving beyond mobile phones and set-top boxes to exploit the growing footprint of Android-based automotive displays. By hijacking privileged firmware update channels, attackers can monetize vehicle internet connections for ad fraud and traffic relaying without affecting core driving functions. For the streaming ecosystem, this highlights a critical vulnerability in the fragmented Android hardware supply chain where infotainment units often lack the rigorous security patching seen in smartphones. Industry stakeholders should monitor for new firmware security standards as automotive manufacturers move to patch these specific TWCore vulnerabilities.
Additional Context
Kaspersky has been the primary research force documenting the BADBOX family of Android-based proxy botnets that MoYu Group operates. In early 2025, Kaspersky published a detailed analysis of BADBOX 2.0 showing the malware had infected over 2 million Android TV boxes and smart displays globally, with compromised devices being sold as residential proxy access on underground forums. The firm identified DoFun as one of the key infrastructure providers monetizing the botnet traffic, and noted that the malware's modular architecture allowed operators to pivot between ad fraud, credential stuffing, and proxy relay services depending on market demand.
The automotive head unit attack represents a natural extension of the BADBOX playbook into a new device category, but it also raises regulatory questions about firmware supply chain security. In the United States, the National Highway Traffic Safety Administration issued guidance in March 2025 requiring automakers to implement software update management systems for connected vehicles, though the guidance focuses on safety-critical systems rather than infotainment firmware. Meanwhile, the European Union's Cyber Resilience Act, which entered into force in December 2024 and will apply to connected products from December 2027, explicitly covers devices with digital elements including automotive infotainment systems, potentially creating compliance obligations for head unit manufacturers who ship unpatched Android builds.
Nokia Deepfield, which operates one of the largest DNS and network intelligence platforms in the industry, has separately tracked the growth of residential proxy networks built from compromised consumer devices. Nokia Deepfield's 2025 DDoS Threat Intelligence Report found that residential proxy traffic originating from IoT and Android-based devices grew 340% year over year, with a significant share attributed to botnet families like BADBOX that repurpose consumer hardware. The report noted that automotive and set-top box devices are particularly attractive to botnet operators because they maintain always-on broadband connections with high uptime, making them more valuable per node than typical mobile phone proxies. For streaming platforms and ad-tech vendors, the proliferation of these proxy networks complicates traffic quality measurement and increases the risk of ad fraud attributed to legitimate viewing sessions.
Read full article at gbhackers.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source