A routine software update feature in Android-based vehicle head units has become the entry point for a new malware campaign targeting connected car screens.
The malware uses a multi-stage downloader designed for ad fraud and proxy botnet activity. It targets head units used for music, navigation and some vehicle functions, taking advantage of the internet connection used for regular software updates.
Security researchers identified the activity while tracking Android threats in June 2026. They described it as the first documented head-unit malware campaign to use a device-specific infection route and linked it to the MoYu Group, which has ties to BADBOX. The affected firmware design enabled the attack, while the vendor said the security issues had been fixed.
The campaign focuses on TWCore, a legitimate system application that handles analytics and head-unit software updates. An MQTT broker on the cardoor[.]cn infrastructure sent APK download details to the device. A setting called installNotExists allowed TWCore to install an app that was not originally present.
Telemetry showed the malware being placed in TWCore’s update cache and installed through the com.tw.core package.
The first component, JarService, has no user interface. It decrypts embedded data and launches the next payload. A second-stage loader sends device information to an attacker-controlled server and receives another download link. The third stage regularly checks in, collects details such as the device model, display resolution, Wi-Fi network name and MAC address, and receives new commands or configuration data.
Unlike common phone scams, the attack does not depend on fake messages, malicious ads or app-store downloads.
The final payload can display advertisements, generate fraudulent clicks, download additional code and open web content in the background. Operators also used commands to download a reverse-proxy module called zhima, allowing infected head units to relay traffic for others.
The attribution is based on malware naming, shared infrastructure and similarities with earlier MoYu Group activity linked to BADBOX, including a malicious TV-box app.
The report found no evidence that the malware directly controls steering, braking or other safety-critical systems. However, a compromised infotainment system can create privacy, connectivity and trust risks.
Owners should use verified manufacturer or dealer update channels, check whether their head unit has received the relevant security fix, and avoid unknown software or USB media. Manufacturers should use signed update packages, verify remote instructions and maintain ways to revoke malicious updates.
Also read: Viksit Workforce for a Viksit Bharat
Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter
About us:
The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.


