A newly uncovered Android malware campaign has turned car infotainment screens into an unexpected target.
Rather than tricking drivers into installing a suspicious app, attackers used the software update path already built into Android-based head units.
The malware is a multi-stage downloader for ad fraud and a proxy botnet. It targets connected vehicle screens that handle music, navigation, and some vehicle functions, exploiting the same internet access that enables routine software updates.
That makes a trusted maintenance feature the entry point for a wider criminal operation. Analysts at Securelist identified the malware while monitoring Android threats in June 2026 and reconstructed the full infection chain.
Researchers called it the first documented head-unit malware using a device-specific infection route and attributed it to the MoYu Group, linked to BADBOX.
.webp)
Securelist said in a report shared with Cyber Security News (CSN) that the affected firmware design enabled the distribution, while the vendor reported that it had fixed the security issues. The finding expands concern beyond phones and televisions, as connected screens become standard in vehicles.
Hackers Infect Android Car Screens
The attack centers on TWCore, a legitimate system application that collects analytics and updates head-unit software.
An MQTT broker on the cardoor[.]cn infrastructure sent details of APK files for download. A setting called installNotExists could instruct TWCore to install an app that was not originally on the device, creating the opening for the malicious package.
Telemetry showed the unknown malware being placed in TWCore’s update cache and installed by the com.tw.core package.
The first component, JarService, has no user interface. It decrypts embedded data and starts the next payload, keeping the infection out of a driver’s view.
.webp)
A second-stage loader then reports device information to an attacker server and receives a link for the next component.
The third stage checks in at regular intervals, collects information such as the device model, display resolution, Wi-Fi network name, and MAC address, then receives fresh configuration data or commands.
This chain differs from familiar phone scams because it does not begin with a fake text, a malicious advert, or an app-store lure.
Earlier BADBOX Android device infections showed how compromised firmware can expose connected devices before users realize anything is wrong. The new case moves that risk directly into the vehicle environment.
From Screen to Proxy Network
The final payload can display advertisements, generate fraudulent clicks, download more code, and open web content in the background.
Researchers found that operators were using commands to fetch a reverse-proxy module named zhima, allowing an infected head unit to relay traffic for someone else. This turns a car screen into part of a hidden network.
The attribution rests on malware naming, shared infrastructure, and overlap with previous activity tied to MoYu Group. The researchers also linked the operation to a malicious TV-box app and noted common infrastructure with campaigns associated with BADBOX.
Readers can compare the pattern with Vo1d Android TV botnet, which also demonstrated the scale that connected Android devices can offer attackers.
.webp)
The report does not show the malware directly controlling steering, braking, or other safety-critical systems. Still, any compromised infotainment device can create privacy, connectivity, and trust problems.
The wider automotive risk is clear from a Nissan Leaf infotainment flaw, where researchers described how a separate weakness could lead from an in-car system toward vehicle functions.
Owners should install only updates supplied through verified manufacturer or dealer channels, ask whether their head unit has received the relevant security fix, and avoid connecting unknown software or USB media.
Manufacturers should restrict update services to signed packages, validate every remote instruction, and keep a clear way to revoke malicious updates.
That is essential when a dashboard screen is also an internet-connected computer. They should also monitor manufacturer advisories and report unexplained app installations, network prompts, or system behavior quickly.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 hash | ba27951b4ee1c341f4415d033369ecd3 |
JarService stage 1 sample |
| SHA-256 hash | d63bacd6d6709dd68a10ef9d374c7835 |
JarService stage 1 sample |
| SHA-256 hash | 6c2e34b30da42085240ede53ab6107d4 |
JarService stage 1 sample |
| SHA-256 hash | 8b5e513144a6138a966ea59e68bf9da2 |
JarService stage 1 sample |
| SHA-256 hash | e119845877089d6f4b0a70dc7388f316 |
JarService stage 1 sample |
| SHA-256 hash | e9f3a0dab6949ce2cddab9e0aa80ae1a |
Stage 2 loader sample |
| SHA-256 hash | 0fbaa7092204f4b1494e0b840b014774 |
Stage 3 loader/clicker sample |
| SHA-256 hash | 1dcf031c40ce456b6a36a00b0acf3d11 |
Stage 3 loader/clicker sample |
| SHA-256 hash | 44b6b213a6a3f299eaf88e078de95ecb |
Stage 3 loader/clicker sample |
| SHA-256 hash | 67dc78e544ebce16b85dc7c195dfbc58 |
Stage 3 loader/clicker sample |
| SHA-256 hash | 9642ae619b3165d23c6349002d1abe24 |
Stage 3 loader/clicker sample |
| SHA-256 hash | b067d5b0dbecbd6498bcdfba45dba77e |
Stage 3 loader/clicker sample |
| SHA-256 hash | f0e3f7eba2cde91e2dedb921bab47422 |
Stage 3 loader/clicker sample |
| SHA-256 hash | 412e9243f2981bbea3894254d105b3b8 |
zhima reverse-proxy module |
| SHA-256 hash | 71ab5517f71866279d0d87d37f2ae320 |
zhima reverse-proxy module |
| SHA-256 hash | 89ef78f716a75964539f2db6520be362 |
zhima reverse-proxy module |
| SHA-256 hash | a4223ce4288a230d1e6c3ff2c7639045 |
zhima reverse-proxy module |
| SHA-256 hash | bd4d81cd27125ad3d9a114922d468499 |
zhima reverse-proxy module |
| SHA-256 hash | c6bfb1643ac7474ed8a7b4f96a187fdb |
zhima reverse-proxy module |
| MD5 hash | de77c3303e93c9450424759f1741441c |
zhima reverse-proxy module |
| SHA-256 hash | f8cf8c23ff597700d471fb7767df8bac |
zhima reverse-proxy module |
| SHA-256 hash | 2a64c3efc11bf224aa54f24e876446c9 |
TWCore updater sample |
| SHA-256 hash | 7a4d3ba2dacccfdda55859a5dfee2671 |
TWCore updater sample |
| SHA-256 hash | ea24487996eb70c1780922fb3063bcc5 |
TWCore updater sample |
| MD5 hash | 3AD4BF5A86D26FFBF09CAE42AF330A98 |
Related TV-box app, com.abc.nexus |
| Domain | xmsae[.]sbs |
Malware infrastructure |
| Domain | ishano456[.]sbs |
Malware infrastructure |
| Domain | xshaon123[.]sbs |
Malware infrastructure |
| Domain | kshahnd[.]sbs |
Malware infrastructure |
| Domain | mdsjhd[.]sbs |
Malware infrastructure |
| Domain | nmnsny[.]sbs |
Malware infrastructure |
| Domain | kookjar[.]com |
Malware infrastructure |
| Domain | ty54fgd435[.]my |
Malware infrastructure |
| Domain | ue886578433[.]online |
Malware infrastructure |
| Domain | ty4523[.]space |
Malware infrastructure |
| Domain | cardoor[.]cn |
MQTT update-message infrastructure |
| Domain | admin.uipoxy[.]com |
zhima administration infrastructure |
| Domain | pxyedge[.]com |
Related registration document host |
| Domain | proxyforu[.]com |
Related proxy-service infrastructure |
| IP address | 144.217.243[.]201 |
Payload-hosting and command infrastructure |
| IP address | 107.151.248[.]132 |
zhima module configuration |
| IP address | 128.14.210[.]58 |
zhima command-and-control infrastructure |
| URL | hxxp://144.217.243[.]201/vr34der34/dex3.68.png |
Stage 3 payload download |
| URL | hxxp://144.217.243[.]201/vr34der34/sh65.io |
zhima module download |
| URL | hxxps://api.kookjar[.]com/sayhi?channel=daihai&uuid={get_uuid_10} |
HTTP command endpoint |
| URL | hxxp://t2.kshahnd[.]sbs |
Stage 3 command host |
| URL | hxxp://t2.mdsjhd[.]sbs |
Stage 3 command host |
| URL | hxxp://t2.nmnsny[.]sbs |
Stage 3 command host |
| URL | hxxps://t2.nmnsny[.]sbs |
Stage 3 command host |
| URL | hxxp://a2.kshahnd[.]sbs |
Stage 3 update host |
| URL | hxxp://a2.mdsjhd[.]sbs |
Stage 3 update host |
| URL | hxxp://a2.nmnsny[.]sbs |
Stage 3 update host |
| URL | hxxps://a2.nmnsny[.]sbs |
Stage 3 update host |
| URL | hxxp://admin.uipoxy[.]com/proxy/u/login |
zhima administration panel |
| URL | hxxps://proxyforu[.]com |
Related proxy-service website |
| URL | hxxp://ovcloudcontrol.cdn.cardoor[.]cn/upgrade/2026-06-08/bd80bd3c3d0e4bf6b5b4a825650d01f5.apk |
JarService download address |
| URL | hxxp://ovcloudcontrol.cdn.cardoor[.]cn/upgrade/2025-06-10/fe71af9ecf174de48d2b2ccc2c15fb04.apk |
JarService download address |
| URL | hxxp://ovcloudcontrol.cdn.cardoor[.]cn/upgrade/2024-11-07/fa831c3c23824b99871163387bcda7ad.apk |
JarService download address |
| Android package | com.tw.core |
TWCore updater package associated with installation |
| Android package | com.tw.jar1 |
JarService package reported to the attacker server |
| Android package | com.abc.nexus |
Related malicious TV-box application |
| Module name | zhima |
Reverse-proxy payload module |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC