news.mlab.sh
Back to the feed
threat-intel

The invisible passenger in your car

High
Image: Securelist
Summary

Researchers at Securelist discovered a new Android malware campaign targeting automotive head units, orchestrated by the MoYu Group, a group linked to the BADBOX botnet. The malware, delivered through legitimate system updates, installs a multi-stage dropper that ultimately builds a proxy botnet. The infection chain involves a dropper (JarService), a loader, and a reverse proxy module (zhima), all designed to monetize device computing power through ad fraud and proxy services. The campaign highlights the ongoing threat posed by BADBOX and the evolving methods used to compromise IoT devices.

Read the full article at Securelist

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.