Tech & AI News
Hacker News

Malware infects Android-based automotive head unit firmware

The researchers uncovered a multi-stage Android downloader that installs without a UI and uses automotive head-unit firmware updaters to spread, creating an ad-fraud and proxy botnet. The infection chain leverages the legitimate TWCore app, which receives malicious APK download commands via an MQTT broker on cardoor.cn, and is attributed with high confidence to the MoYu Group linked to the BADBOX botnet. Kaspersky detects the components under heuristics HEUR:Trojan-Dropper.AndroidOS.Agent.vu, HEUR:Trojan-Downloader.AndroidOS.Agent.ov, HEUR:Trojan-Proxy.AndroidOS.Zhima.*, and HEUR:Trojan.AndroidOS.Vo1d.*.