Hackers Infect Android Car Screens Through Their Built-In Software Update System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A newly uncovered Android malware campaign has turned car infotainment screens into an unexpected target.

Rather than tricking drivers into installing a suspicious app, attackers used the software update path already built into Android-based head units.

The malware is a multi-stage downloader for ad fraud and a proxy botnet. It targets connected vehicle screens that handle music, navigation, and some vehicle functions, exploiting the same internet access that enables routine software updates.

That makes a trusted maintenance feature the entry point for a wider criminal operation. Analysts at Securelist identified the malware while monitoring Android threats in June 2026 and reconstructed the full infection chain.

Researchers called it the first documented head-unit malware using a device-specific infection route and attributed it to the MoYu Group, linked to BADBOX.

Head unit infection scheme (Source - Securelist)
Head unit infection scheme (Source – Securelist)

Securelist said in a report shared with Cyber Security News (CSN) that the affected firmware design enabled the distribution, while the vendor reported that it had fixed the security issues. The finding expands concern beyond phones and televisions, as connected screens become standard in vehicles.

Hackers Infect Android Car Screens

The attack centers on TWCore, a legitimate system application that collects analytics and updates head-unit software.

An MQTT broker on the cardoor[.]cn infrastructure sent details of APK files for download. A setting called installNotExists could instruct TWCore to install an app that was not originally on the device, creating the opening for the malicious package.

Telemetry showed the unknown malware being placed in TWCore’s update cache and installed by the com.tw.core package.

The first component, JarService, has no user interface. It decrypts embedded data and starts the next payload, keeping the infection out of a driver’s view.

Decrypting the stage 3 payload (Source - Securelist)
Decrypting the stage 3 payload (Source – Securelist)

A second-stage loader then reports device information to an attacker server and receives a link for the next component.

The third stage checks in at regular intervals, collects information such as the device model, display resolution, Wi-Fi network name, and MAC address, then receives fresh configuration data or commands.

This chain differs from familiar phone scams because it does not begin with a fake text, a malicious advert, or an app-store lure.

Earlier BADBOX Android device infections showed how compromised firmware can expose connected devices before users realize anything is wrong. The new case moves that risk directly into the vehicle environment.

From Screen to Proxy Network

The final payload can display advertisements, generate fraudulent clicks, download more code, and open web content in the background.

Researchers found that operators were using commands to fetch a reverse-proxy module named zhima, allowing an infected head unit to relay traffic for someone else. This turns a car screen into part of a hidden network.

The attribution rests on malware naming, shared infrastructure, and overlap with previous activity tied to MoYu Group. The researchers also linked the operation to a malicious TV-box app and noted common infrastructure with campaigns associated with BADBOX.

Readers can compare the pattern with Vo1d Android TV botnet, which also demonstrated the scale that connected Android devices can offer attackers.

The malware operator registration page (Source - Securelist)
The malware operator registration page (Source – Securelist)

The report does not show the malware directly controlling steering, braking, or other safety-critical systems. Still, any compromised infotainment device can create privacy, connectivity, and trust problems.

The wider automotive risk is clear from a Nissan Leaf infotainment flaw, where researchers described how a separate weakness could lead from an in-car system toward vehicle functions.

Owners should install only updates supplied through verified manufacturer or dealer channels, ask whether their head unit has received the relevant security fix, and avoid connecting unknown software or USB media.

Manufacturers should restrict update services to signed packages, validate every remote instruction, and keep a clear way to revoke malicious updates.

That is essential when a dashboard screen is also an internet-connected computer. They should also monitor manufacturer advisories and report unexplained app installations, network prompts, or system behavior quickly.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 hash ba27951b4ee1c341f4415d033369ecd3 JarService stage 1 sample
SHA-256 hash d63bacd6d6709dd68a10ef9d374c7835 JarService stage 1 sample
SHA-256 hash 6c2e34b30da42085240ede53ab6107d4 JarService stage 1 sample
SHA-256 hash 8b5e513144a6138a966ea59e68bf9da2 JarService stage 1 sample
SHA-256 hash e119845877089d6f4b0a70dc7388f316 JarService stage 1 sample
SHA-256 hash e9f3a0dab6949ce2cddab9e0aa80ae1a Stage 2 loader sample
SHA-256 hash 0fbaa7092204f4b1494e0b840b014774 Stage 3 loader/clicker sample
SHA-256 hash 1dcf031c40ce456b6a36a00b0acf3d11 Stage 3 loader/clicker sample
SHA-256 hash 44b6b213a6a3f299eaf88e078de95ecb Stage 3 loader/clicker sample
SHA-256 hash 67dc78e544ebce16b85dc7c195dfbc58 Stage 3 loader/clicker sample
SHA-256 hash 9642ae619b3165d23c6349002d1abe24 Stage 3 loader/clicker sample
SHA-256 hash b067d5b0dbecbd6498bcdfba45dba77e Stage 3 loader/clicker sample
SHA-256 hash f0e3f7eba2cde91e2dedb921bab47422 Stage 3 loader/clicker sample
SHA-256 hash 412e9243f2981bbea3894254d105b3b8 zhima reverse-proxy module
SHA-256 hash 71ab5517f71866279d0d87d37f2ae320 zhima reverse-proxy module
SHA-256 hash 89ef78f716a75964539f2db6520be362 zhima reverse-proxy module
SHA-256 hash a4223ce4288a230d1e6c3ff2c7639045 zhima reverse-proxy module
SHA-256 hash bd4d81cd27125ad3d9a114922d468499 zhima reverse-proxy module
SHA-256 hash c6bfb1643ac7474ed8a7b4f96a187fdb zhima reverse-proxy module
MD5 hash de77c3303e93c9450424759f1741441c zhima reverse-proxy module
SHA-256 hash f8cf8c23ff597700d471fb7767df8bac zhima reverse-proxy module
SHA-256 hash 2a64c3efc11bf224aa54f24e876446c9 TWCore updater sample
SHA-256 hash 7a4d3ba2dacccfdda55859a5dfee2671 TWCore updater sample
SHA-256 hash ea24487996eb70c1780922fb3063bcc5 TWCore updater sample
MD5 hash 3AD4BF5A86D26FFBF09CAE42AF330A98 Related TV-box app, com.abc.nexus
Domain xmsae[.]sbs Malware infrastructure
Domain ishano456[.]sbs Malware infrastructure
Domain xshaon123[.]sbs Malware infrastructure
Domain kshahnd[.]sbs Malware infrastructure
Domain mdsjhd[.]sbs Malware infrastructure
Domain nmnsny[.]sbs Malware infrastructure
Domain kookjar[.]com Malware infrastructure
Domain ty54fgd435[.]my Malware infrastructure
Domain ue886578433[.]online Malware infrastructure
Domain ty4523[.]space Malware infrastructure
Domain cardoor[.]cn MQTT update-message infrastructure
Domain admin.uipoxy[.]com zhima administration infrastructure
Domain pxyedge[.]com Related registration document host
Domain proxyforu[.]com Related proxy-service infrastructure
IP address 144.217.243[.]201 Payload-hosting and command infrastructure
IP address 107.151.248[.]132 zhima module configuration
IP address 128.14.210[.]58 zhima command-and-control infrastructure
URL hxxp://144.217.243[.]201/vr34der34/dex3.68.png Stage 3 payload download
URL hxxp://144.217.243[.]201/vr34der34/sh65.io zhima module download
URL hxxps://api.kookjar[.]com/sayhi?channel=daihai&uuid={get_uuid_10} HTTP command endpoint
URL hxxp://t2.kshahnd[.]sbs Stage 3 command host
URL hxxp://t2.mdsjhd[.]sbs Stage 3 command host
URL hxxp://t2.nmnsny[.]sbs Stage 3 command host
URL hxxps://t2.nmnsny[.]sbs Stage 3 command host
URL hxxp://a2.kshahnd[.]sbs Stage 3 update host
URL hxxp://a2.mdsjhd[.]sbs Stage 3 update host
URL hxxp://a2.nmnsny[.]sbs Stage 3 update host
URL hxxps://a2.nmnsny[.]sbs Stage 3 update host
URL hxxp://admin.uipoxy[.]com/proxy/u/login zhima administration panel
URL hxxps://proxyforu[.]com Related proxy-service website
URL hxxp://ovcloudcontrol.cdn.cardoor[.]cn/upgrade/2026-06-08/bd80bd3c3d0e4bf6b5b4a825650d01f5.apk JarService download address
URL hxxp://ovcloudcontrol.cdn.cardoor[.]cn/upgrade/2025-06-10/fe71af9ecf174de48d2b2ccc2c15fb04.apk JarService download address
URL hxxp://ovcloudcontrol.cdn.cardoor[.]cn/upgrade/2024-11-07/fa831c3c23824b99871163387bcda7ad.apk JarService download address
Android package com.tw.core TWCore updater package associated with installation
Android package com.tw.jar1 JarService package reported to the attacker server
Android package com.abc.nexus Related malicious TV-box application
Module name zhima Reverse-proxy payload module

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Hackers Infect Android Car Screens Through Their Built-In Software Update System appeared first on Cyber Security News.