securelist · Crawled Sep 2, 2026

The invisible passenger in your car

35 IoCs 1 Malware
Read original article ↗

AI Summary

A new multi-stage Android malware has been discovered targeting automotive head units via compromised firmware update mechanisms. The malware, distributed through the legitimate TWCore app's update function, operates in three stages: an initial dropper (JarService), a loader, and a final stage that performs ad fraud and establishes a reverse proxy botnet. The infection chain leverages MQTT-based commands and downloads malicious payloads from attacker-controlled servers. This campaign is attributed to the MoYu Group, a threat actor associated with the BADBOX botnet, based on code similarities, infrastructure overlap, and naming patterns observed in other compromised devices such as TV set-top boxes.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 35 extracted

Type Value Detail
MD5 ba27951b4ee1c341f4415d033369ecd3 Details →
MD5 d63bacd6d6709dd68a10ef9d374c7835 Details →
MD5 6c2e34b30da42085240ede53ab6107d4 Details →
MD5 8b5e513144a6138a966ea59e68bf9da2 Details →
MD5 e119845877089d6f4b0a70dc7388f316 Details →
MD5 e9f3a0dab6949ce2cddab9e0aa80ae1a Details →
MD5 0fbaa7092204f4b1494e0b840b014774 Details →
MD5 1dcf031c40ce456b6a36a00b0acf3d11 Details →
MD5 44b6b213a6a3f299eaf88e078de95ecb Details →
MD5 67dc78e544ebce16b85dc7c195dfbc58 Details →
MD5 9642ae619b3165d23c6349002d1abe24 Details →
MD5 b067d5b0dbecbd6498bcdfba45dba77e Details →
MD5 f0e3f7eba2cde91e2dedb921bab47422 Details →
MD5 412e9243f2981bbea3894254d105b3b8 Details →
MD5 71ab5517f71866279d0d87d37f2ae320 Details →
MD5 89ef78f716a75964539f2db6520be362 Details →
MD5 a4223ce4288a230d1e6c3ff2c7639045 Details →
MD5 bd4d81cd27125ad3d9a114922d468499 Details →
MD5 c6bfb1643ac7474ed8a7b4f96a187fdb Details →
MD5 de77c3303e93c9450424759f1741441c Details →
MD5 f8cf8c23ff597700d471fb7767df8bac Details →
Domain xmsae[.]sbs Details →
Domain ishano456[.]sbs Details →
Domain xshaon123[.]sbs Details →
Domain kshahnd[.]sbs Details →
Domain mdsjhd[.]sbs Details →
Domain nmnsny[.]sbs Details →
Domain kookjar[.]com Details →
Domain ty54fgd435[.]my Details →
Domain ue886578433[.]online Details →
Domain ty4523[.]space Details →
IP 144[.]217[.]243[.]201 Details →
IP 107[.]151[.]248[.]132 Details →
IP 128[.]14[.]210[.]58 Details →
Domain ovcloudcontrol[.]cdn[.]cardoor[.]cn Details →

MITRE ATT&CK TTPs 4 techniques