Malware infects Android-based automotive head unit firmware
Summary
Kaspersky Securelist analyzes Android head-unit malware that uses the device update mechanism to install a multi-stage downloader, ultimately forming a proxy botnet. The report attributes the activity to the MoYu Group (BADBOX) and documents Stage 1 JarService, Stage 2 loader, and Stage 3 zhima modules, with indicators of compromise and IPC artifacts. This highlights the growing risk of embedded automotive devices being targeted by sophisticated malware.