Back to Blog

Trojan for Car Stereos: How an Updater Hijack Turns Your Vehicle into a Proxy Node

Kaspersky described the first malware for Android car head units: through the legitimate updater TWCore, a module zhima is installed on DoFun car radios, turning them into nodes of a residential proxy pool. We analyze the infection chain, the connection with BADBOX and NetNut, and explain what this changes for those who purchase residential proxies.

📅August 28, 2026
Trojan for Car Stereos: How an Updater Hijack Turns Your Vehicle into a Proxy Node

On August 21, 2026, Kaspersky Lab published an analysis of the first documented malware for Android-based car head units. The infected car stereo does not steal music or track routes; instead, it turns into a node in a residential proxy pool and a clicker for ad fraud. The key aspect of this story is not the car itself, but the delivery method: the attackers did not persuade the manufacturer to embed an SDK; they intercepted its own firmware update mechanism.

What Was Found

The campaign was discovered in June 2026, with a public report released on August 21. The target was head units running firmware from the Chinese company DoFun (Shenzhen Driving Control Technology Co., Ltd), which are aftermarket stereos replacing factory-installed units. Kaspersky confidently associates the operation with the MoYu group, previously known for the BADBOX botnet — a platform that HUMAN Security reported on in 2023 regarding pre-installed backdoors in its firmware.

The infection chain looks like this:

  1. Entry point — the legitimate system application TWCore, which on DoFun devices is responsible for analytics and updates. It receives commands via an MQTT broker on the domain cardoor[.]cn, and the protocol includes a flag installNotExists — permission to install an application that is not yet on the device.
  2. First stage — the JarService dropper without an interface. The payload inside is encrypted with XOR using a one-byte linear shifting key.
  3. Second stage — the loader: it sends a POST request with device information to the command server and receives links for the next stage.
  4. Third stage — the clicker and reverse proxy loader: it connects to C2 every 90 minutes, supports nine types of commands (including http, web, loadlib2, deeplink), and pulls the zhima module.

The zhima module is the essence of the operation: it opens a reverse connection to command servers (the report mentions addresses like 107.151.248[.]132 and 128.14.210[.]58, ports 1337, 7777, 8888, 15000) and turns the device into a proxy node. Head units are almost perfectly suited for this role: many have a SIM card slot and a constant internet connection — necessary for navigation and those very updates.

Why This is a Different Level, Not Just "Another Botnet"

Until now, the widespread narrative about the origin of "gray" residential IPs looked like this: the manufacturer of a cheap device or the developer of a free application consciously embeds a monetization SDK and gets paid for it, while the user agrees to an unread EULA. In a report on dismantling the NetNut network, Google outlines two channels through which home devices enter proxy networks: malware is pre-installed before purchase, or the user downloads an application with hidden proxy code themselves.

The DoFun case does not fit either of these scenarios. Here, the vendor is neither involved nor aware: their trusted update delivery channel has been hijacked. Kaspersky notified the company, and according to researchers, the issue was resolved. However, the practical takeaway for the market is unpleasant: verifying the origin of a pool based on the principle of "show us contracts with partners and consent text" is no longer sufficient. A node can be obtained without any involvement from the device's manufacturer.

The second important detail is the commercial framework. Researchers found an admin panel on the domain admin.uipoxy[.]com requiring invite codes for registration. This means it is not "a botnet for the sake of a botnet," but a functioning showcase where traffic through infected devices is sold to someone. Simultaneously, Nokia Deepfield independently discovered the same zhima module in TV set-top boxes. In other words, one pool is being gathered from different classes of devices — set-top boxes and stereos.

The scale of neighboring operations provides a guideline for why this is happening. On July 2, 2026, Google, in collaboration with the FBI, IRS-CI, and Lumen, shut down the NetNut network: Google estimated over 2 million compromised devices. Just in one week of June, GTIG telemetry recorded 316 separate clusters of activity routing through suspected NetNut nodes — ranging from cybercrime to espionage groups. We analyzed the mechanics of this market separately in the article about the economics of the residential pool.

Why the Market Tolerates This

The answer is simple — price. According to Proxyway's research for 2026, at least 56 new proxy vendors appeared on the market between early 2025 and March 2026, and most new residential services are white label on top of someone else's infrastructure; a significant portion is promoted not through search but through forums like BlackHatWorld. In the lower segment, a gigabyte of residential traffic costs $0.30 or less — a price that is physically unattainable if the pool is gathered through payments to partners and contracts with operators. These offers are driving the prices of the entire market down.

The upper tier, meanwhile, is growing: Bright Data reported a 50% annual growth and an annual revenue of around $300 million, NetNut showed +28% until its July shutdown, while other market participants reported growth ranging from 30% to doubling year over year. This means that the demand for data and access is growing faster than the legal supply of nodes — and the gap is being filled by stories like zhima in car stereos.

What This Means for Proxy Buyers

The temptation to brush this off is understandable: "I don't own a Chinese car stereo, this doesn't concern me." It does concern you — but from the other side of the counter. If your provider purchases traffic at the lower tier of the market, you may be working through exactly such nodes. The consequences are quite practical:

  • IP Neighborhood. Through the same node at the same time, click fraud, password cracking, or scanning may occur. Anti-fraud platforms do not see you, but the overall reputation of the address — and they will terminate the session before you can do anything.
  • Blocklists. After the publication of reports and takedown operations, ranges and specific addresses quickly spread across reputation databases. An IP purchased as "clean" yesterday may find itself on lists today.
  • Node Instability. A car stereo is not a home router. The car is moving, the device switches between cells, ASN and geo change; at night, the car sits with the ignition off, and the node simply disappears in the middle of your session. For long tasks like authorization or working with a shopping cart, this guarantees interruptions.
  • Legal and Reputational Risk. Traffic going through a knowingly compromised device is a bad position in any dispute, especially if your contractor promised "ethical user consents."

How to Check the Pool Now

Questions for the provider should be rephrased. Previously, it was enough to ask "where is the IP from" — now it is more important to understand how control is maintained throughout the life of the node:

  1. What is the model for obtaining the node. A proprietary partner network with payments and explicit opt-in, rental from an operator, ISP contract — or bulk purchase from an unnamed upstream. Refusal to disclose the upstream level is, in itself, an answer.
  2. Is there continuous reputation monitoring. It’s not enough to check a node once: an address that is clean at entry can deteriorate over weeks. Ask how often and by what sources the pool is re-evaluated and what happens to an address that gets on a blocklist.
  3. What do they do during a takedown operation. After the July incident with NetNut, the market shuffled. A reputable operator has a clear answer about how they replace dropped segments, rather than silence and declining quality.
  4. Check for yourself. Before a serious task, run the provided addresses through reputation databases — how to do this is explained in the guide on checking IPs in blocklists. Plus, a simple behavioral test: if a "residential" address changes ASN and city within half an hour, it’s not an apartment.

A practical guideline: for tasks where session predictability is important, it’s wiser to use residential proxies with transparent pool origins, and where a mobile operator is specifically needed — mobile proxies with a clear set of networks, rather than a random SIM card in someone else's car.

If You Have an Android Stereo or Set-Top Box

A separate part of the audience consists of owners of those very devices. There is no universal "antivirus for stereos," but at least some steps can be taken:

  • Check if the firmware is updated: DoFun, according to Kaspersky, has closed the vulnerability, so an update makes sense.
  • Do not provide the device with constant internet access if it is not needed: without a network, the node is useless. Many aftermarket stereos only need internet access occasionally.
  • Monitor traffic on your router or through the SIM card: a constant outgoing flow from a device that "just plays music" is a direct sign. The same applies to TV set-top boxes with unofficial firmware.
  • Do not install unofficial builds and clients from third-party stores: in the NetNut case, this channel accounted for a significant portion of nodes.

Conclusion

The DoFun story is interesting not for the number of infected machines — which has not yet been disclosed and is likely small. What is interesting is the precedent: to gather a residential pool, it is no longer necessary to negotiate with the device manufacturer. It is enough to hijack its updater. This means that the lower price tier of the proxy market will continue to be filled with nodes of which neither the device owner nor its vendor is aware — with all the consequences for those who work through them. The difference between a cheap gigabyte and a predictable one lies precisely in this.