
Kaspersky researcher Dmitry Kalinin has documented what the firm calls the first malware family specifically built to infect Android-based car head units — the touchscreen entertainment and navigation systems found in millions of vehicles worldwide, often sold as factory-fitted units or aftermarket upgrades.
The malware exploits TWCore (“com.tw.core”), a legitimate system application pre-installed on head units manufactured using DoFun firmware. TWCore normally handles analytics and software updates, pulling APK files over MQTT from a server at the “cardoor[.]cn” subdomain. Threat actors linked to the BADBOX botnet compromised that update channel to push a dropper named JarService directly to head units — no user interaction required. JarService loads a payload that runs silently in the background, checking in with a command-and-control server every 90 minutes to receive ad fraud instructions, download additional malicious modules, and relay network traffic through the infected vehicle. Because the head units connect to the internet via a SIM card slot for navigation updates, they provide always-on network access that the botnet operators can monetize. Kaspersky found seven variants of the final payload dating back to version “3.57,” all retrieved simply by incrementing the version number in the download path. Following responsible disclosure, the vulnerability in DoFun’s software distribution mechanism has been addressed.
