THE article discusses a new Android malware threat targeting automotive head units, identified by Kaspersky Labs as being delivered through compromised firmware update tools. The malware, associated with the MoYu Group and linked to the BADBOX botnet, installs silently via a system updater named TWCore, which can run packages with elevated privileges without user interaction.
The infection chain involves multiple stages, including the deployment of a dropper called JarService that facilitates communication with external servers and executes further malicious payloads. The malware can modify clipboard data, execute browser actions, and download additional modules. Kaspersky emphasizes the novelty of this threat as the first documented case affecting car head units. Recommendations for defense include ensuring firmware updates and monitoring data usage to prevent infections.