Hackers use car software update to plant proxy botnet malware on Android head units

Hackers have infected Android-based car head units with malware that turns the devices into proxy botnet nodes for monetization, Kaspersky researchers said on Thursday. The attack uses a legitimate software-update app from DoFun, a Chinese automotive provider, to download malicious code that establishes contact with attacker-controlled servers and supports nine commands including web requests and arbitrary code execution.
Kaspersky attributed the operation to the MoYu group, previously linked to the BadBox botnet, and said it represents the first documented malware infection chain targeting car head units. The malware does not interfere with driving or critical vehicle systems but appears designed for advertising fraud and turning internet-connected units into residential proxy nodes. Kaspersky notified DoFun, which said it had resolved the problem, Bill Toulas reports for BleepingComputer.