<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Android Head Unit Firmware - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/android-head-unit-firmware/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 21 Aug 2026 16:30:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/android-head-unit-firmware/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>MoYu Group Exploits Automotive Firmware Update Mechanism for Botnet Deployment</title><link>https://feed.craftedsignal.io/briefs/2026-08-android-car-malware/</link><pubDate>Fri, 21 Aug 2026 16:30:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-android-car-malware/</guid><description>The MoYu Group is targeting DoFun Android-based vehicle head units by weaponizing the legitimate TWCore system update application to distribute JarService malware, turning automotive hardware into nodes for ad fraud and proxy botnets.</description><content:encoded><![CDATA[<p>Cybersecurity researchers have identified a campaign targeting Android-based automotive head units manufactured by DoFun. Discovered by Kaspersky in June 2026, the activity involves the abuse of the legitimate &quot;TWCore&quot; (com.tw.core) system application responsible for firmware updates and analytics. The MoYu Group, linked to the broader BADBOX ad fraud and proxy botnet scheme, weaponized the device's MQTT-based update channel to deliver a malicious dropper named JarService. This multi-stage infection allows attackers to establish persistent command-and-control communication, exfiltrate sensitive device information (including MAC addresses and Wi-Fi identifiers), and execute arbitrary commands or modules. By leveraging the head unit's internet connectivity and Android-based environment, attackers repurpose vehicle hardware as residential proxy nodes and ad fraud engines. This represents the first documented case of an infection chain specifically tailored to automotive head unit firmware update mechanisms.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker utilizes the legitimate system application TWCore (com.tw.core) to initiate a firmware check via a compromised MQTT message broker hosted at cardoor.cn.</li>
<li>The update mechanism triggers an automatic download of a malicious APK file to the directory &lt;TWCore external cache dir&gt;/push/apk/.</li>
<li>The JarService dropper is executed on the Android automotive head unit, bypassing standard application installation prompts.</li>
<li>JarService initiates an HTTP POST request to the hardcoded C2 infrastructure at 144.217.243.201 to report implant metadata.</li>
<li>The C2 server returns a download link for the secondary payload, identified by versioned filenames such as &quot;dex3.68.png&quot;.</li>
<li>The secondary payload is deployed as a background user application without a user interface to maintain persistence.</li>
<li>The malware beacons to the C2 endpoint &quot;/cpc/api/task&quot; every 90 minutes, retrieving updated configurations or command identifiers (productIds).</li>
<li>Attackers issue commands to the vehicle head unit to perform ad fraud, execute JavaScript in a WebView, or install the &quot;zhima&quot; reverse proxy module for botnet traffic.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The compromise of vehicle head units facilitates large-scale ad fraud and the creation of residential proxy networks. Because these units possess persistent internet connectivity via SIM slots, they serve as high-availability nodes for botnet operators. Successful exploitation allows attackers to steal device hardware identifiers and execute arbitrary code on the vehicle's multimedia system, potentially exposing the user's Wi-Fi network and internal connectivity to malicious traffic routing.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor network traffic for connections to the domain cardoor.cn or the IP 144.217.243.201 and block these at the enterprise DNS resolver or firewall.</li>
<li>Audit installed APKs on vehicle head unit firmware for the presence of the &quot;JarService&quot; dropper and the &quot;zhima&quot; reverse proxy module.</li>
<li>Contact the automotive vendor to verify the integrity of the firmware update channel and ensure that the TWCore MQTT broker is not communicating with unauthorized domains.</li>
<li>Restrict network communication from automotive head units to only known, verified update servers to prevent unauthorized remote module downloads.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item></channel></rss>