【文章标题】:Malware infects Android-based automotive head unit firmware 【文章标题】:恶意软件感染基于安卓的车机固件
【文章正文】: While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. This led us to suspect the app might be reaching users’ devices without their knowledge. Further investigation confirmed that hypothesis and allowed us to reconstruct the entire infection chain. 【文章正文】: 在2026年6月监控安卓威胁时,我们发现了一款新的安卓恶意软件。让我们感到不寻常的是,它像普通用户应用一样安装,却完全没有试图伪装成合法软件:它根本没有任何用户界面。这让我们怀疑该应用可能在用户不知情的情况下到达其设备。进一步的调查证实了这一假设,并使我们能够重建整个感染链。
Key findings:
- We identified new Android malware: a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet.
- The malware spread through the built-in updaters of Android-based automotive head unit firmware. This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.
- We attribute this activity, with high confidence, to the MoYu Group, an actor linked to the BADBOX botnet. 关键发现:
- 我们识别出新的安卓恶意软件:一款多阶段下载器,其最终目的是广告欺诈和创建代理僵尸网络。
- 该恶意软件通过基于安卓的车机固件内置更新程序传播。这是首例记录在案的、在汽车车机上发现的、具有针对该类设备特定感染链的恶意软件案例。
- 我们高度确信地将此活动归因于MoYu Group,一个与BADBOX僵尸网络有关联的威胁行为者。
Kaspersky solutions detect the threats described below under the following detection names:
- HEUR:Trojan-Dropper.AndroidOS.Agent.vu
- HEUR:Trojan-Downloader.AndroidOS.Agent.ov
- HEUR:Trojan-Proxy.AndroidOS.Zhima.*
- HEUR:Trojan.AndroidOS.Vo1d.* 卡巴斯基解决方案在以下检测名称下检测到下述威胁:
- HEUR:Trojan-Dropper.AndroidOS.Agent.vu
- HEUR:Trojan-Downloader.AndroidOS.Agent.ov
- HEUR:Trojan-Proxy.AndroidOS.Zhima.*
- HEUR:Trojan.AndroidOS.Vo1d.*
Head unit firmware overview 车机固件概览
A head unit is a system that combines multimedia functions with partial control over certain vehicle functions. Head units may come as part of a car’s factory equipment or as an aftermarket upgrade. The main attack vectors for these systems are compromise via physical access and vulnerabilities in the head unit’s OS or components, both of which we’ve covered previously. 车机是一种将多媒体功能与对某些车辆功能的部分控制相结合的系统。车机可能作为汽车原厂设备的一部分,或作为售后升级件提供。这些系统的主要攻击途径是通过物理访问以及车机操作系统或组件中的漏洞进行入侵,这两方面我们之前都已讨论过。
In some cases, head units run on Android, primarily because it’s convenient for manufacturers: Android’s source code already accounts for use cases within automotive head units. Android also allows manufacturers to add their own system applications during the build process, which they can use for a range of purposes: customizing the UI, adding system components tailored to the vendor’s needs, and more. 在某些情况下,车机运行安卓系统,主要是因为这对制造商来说很方便:安卓的源代码已经考虑了汽车车机内的使用场景。安卓还允许制造商在构建过程中添加自己的系统应用,他们可以将这些应用用于多种目的:定制用户界面、添加针对供应商需求定制的系统组件等等。
Most apps developed for Android devices can also run on an Android-based head unit, and that is true for malware as well. That said, it’s hard to imagine certain categories of smartphone-targeted malware being used to attack a head unit. Banking Trojans are a good example: since mobile banking is used almost exclusively on smartphones, infecting a head unit with a banking Trojan would be a waste of the attacker’s resources. 大多数为安卓设备开发的应用也能在基于安卓的车机上运行,恶意软件也是如此。话虽如此,很难想象某些针对智能手机的恶意软件类别会被用来攻击车机。银行木马就是一个很好的例子:由于移动银行几乎只在智能手机上使用,用车机感染银行木马将是对攻击者资源的浪费。
It’s worth noting that head units often include SIM card slots and can connect to the internet, enabling features like navigation and software updates. Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet – similar to attacks on IoT devices. 值得注意的是,车机通常包含SIM卡插槽,并且可以连接互联网,从而支持导航和软件更新等功能。由于车机通常对攻击者来说没有任何有价值的东西,使用“经典”安卓恶意软件的一种更可能的攻击场景是感染设备,将其招募进僵尸网络——类似于对物联网设备的攻击。
During our research, we found exactly that kind of malware. The design of firmware for DoFun head units enabled attackers to distribute malware. We notified the vendor about the distribution scheme, and they subsequently reported fixing the security issues. 在我们的研究过程中,我们发现的正是这种恶意软件。DoFun车机固件的设计使攻击者能够分发恶意软件。我们已将分发方案通知了供应商,他们随后报告已修复这些安全问题。
Below is the entire infection chain: 以下是完整的感染链:
Let’s look at exactly how these head units became infected. 让我们仔细看看这些车机是如何被感染的。
The TWCore app TWCore应用
TWCore is a legitimate system application responsible for collecting analytics data and updating the head unit software. Let’s take a closer look at how the update function works. TWCore是一个合法的系统应用,负责收集分析数据并更新车机软件。让我们仔细看看更新功能是如何工作的。
The process is fairly simple. An MQTT message broker hosted on the subdomain cardoor[.]cn sends a message containing information about the APK files that need to be downloaded and installed on the head unit. Notably, the object describing this message includes an installNotExists field, a Boolean flag that can be set to true or false. This flag allows TWCore to install apps that weren’t originally present on the device. 这个过程相当简单。托管在子域名cardoor[.]cn上的MQTT消息代理发送一条消息,其中包含需要在车机上下载和安装的APK文件信息。值得注意的是,描述该消息的对象包含一个installNotExists字段,这是一个布尔标志,可以设置为true或false。该标志允许TWCore安装设备上原本不存在的应用。
The APK file is downloaded to
Our telemetry revealed previously unknown malware at these file paths. On top of that, our data indicates that in every observed case, the malware was installed by an app with the package name com.tw.core, which matches the TWCore package name. 我们的遥测数据在这些文件路径上发现了此前未知的恶意软件。除此之外,我们的数据表明,在每一个观察到的案例中,该恶意软件都是由包名为com.tw.core的应用安装的,这与TWCore的包名相符。
Next, we’ll break down the malware installed by TWCore: the JarService dropper. 接下来,我们将分解由TWCore安装的恶意软件:JarService投放器。
Stage 1: the JarService dropper 阶段1:JarService投放器
As mentioned earlier, JarService is a small dropper app with no UI of any kind. It decrypts data stored as encrypted blocks within the Trojan’s code. Each block is XOR-encrypted with a single-byte key that shifts linearly from block to block. The decrypted data contains serialized information about the payload version and entry point, along with the malware’s own code for further loading. 如前所述,JarService是一个小型的投放器应用,没有任何形式的用户界面。它解密存储在木马代码中的加密数据块。每个数据块都使用单字节密钥进行XOR加密,该密钥在数据块之间线性变化。解密后的数据包含有关载荷版本和入口点的序列化信息,以及用于进一步加载的恶意软件自身代码。
In the version of JarService we analyzed, the entry point for the next-stage payload was the wa method of the com.c.j.qbh class. 在我们分析的JarService版本中,下一阶段载荷的入口点是com.c.j.qbh类的wa方法。
Stage 2: the loader 阶段2:加载器
This stage’s payload is a malicious loader. Its code contains encrypted strings that are later used as class names to execute the stage 3 payload using the reflection me 该阶段的载荷是一个恶意加载器。其代码包含加密字符串,这些字符串后来被用作类名,以使用反射 me 执行阶段3载荷。