The invisible passenger in your car
Cybersecurity Classified by Officially
While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. This led us to suspect the app might be reaching users’ devices without their knowledge. Further investigation confirmed that hypothesis and allowed us to reconstruct the entire infection chain.
Key findings:
- We identified new Android malware: a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet.
- The malware spread through the built-in updaters of Android-based automotive head unit firmware. This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.
- We attribute this activity, with high confidence, to the MoYu Group, an actor linked to the BADBOX botnet.
Kaspersky solutions detect the threats described below under the following detection names:
- HEUR:Trojan-Dropper.AndroidOS.Agent.vu
- HEUR:Trojan-Downloader.AndroidOS.Agent.ov
- HEUR:Trojan-Proxy.AndroidOS.Zhima.*
- HEUR:Trojan.AndroidOS.Vo1d.*
Head unit firmware overview
A head unit is a system that combines multimedia functions with partial control over certain vehicle functions. Head units may come as part of a car’s factory equipment or as an aftermarket upgrade. The main attack vectors for these systems are compromise via physical access and vulnerabilities in the head unit’s OS or components, both of which we’ve covered previously.
In some cases, head units run on Android, primarily because it’s convenient for manufacturers: Android’s source code already accounts for use cases within automotive head units. Android also allows manufacturers to add their own system applications during the build process, which they can use for a range of purposes: customizing the UI, adding system components tailored to the vendor’s needs, and more.
This is an extract. The publication continues at the source.
Read the original at the source: https://securelist.com/android-head-unit-malware/121106/
Officially imported this from Kaspersky Securelist’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Kaspersky Securelist — imported from official source
- Official source
- https://securelist.com/feed/ RSS
- Imported
- September 20, 2026 19:52
- Versions
- 1 recorded
- Identity
https://kasperskycontenthub.com/securelist/?p=121106