securelist.com 8/21/2026, 8:20:36 AM · external

The invisible passenger in your car

The invisible passenger in your car
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
MoYu Group

THE article discusses a newly discovered Android malware targeting automotive head units, which are multimedia systems integrated into vehicles. This malware installs like a regular user app, lacking a user interface, indicating potential covert installations. Major findings include that the malware functions as a multi-stage downloader intended for ad fraud and creating a proxy botnet, utilizing vulnerabilities in automotive head unit firmware.

The infection is attributed to the MoYu Group, linked to the BADBOX botnet. The malware's distribution exploits legitimate system update functionalities, marking the first recorded malware affecting car head units. Various stages of the malware and details of its operation—including the use of a legitimate app called TWCore for installation—are thoroughly outlined.

View full article

Article by CyberSIXT