Hackers Exploit Cheap Chinese Car Multimedia Screens to Create Global Botnet
Israeli cybersecurity researchers from Kaspersky have uncovered a novel cyber threat involving inexpensive Android-based multimedia screens installed in vehicles. These aftermarket devices, produced by the Chinese company DoFun, are widely sold online and can be installed in various car brands as a cheaper alternative to original systems. The screens were found to be infected with a malicious software called JarService, distributed through the manufacturer’s legitimate update mechanism via an app named TWCore, which communicates with command servers in China.
The malware operates covertly, collecting detailed hardware and network information and installing a core module called zhima that turns the vehicle’s multimedia system into a proxy node. Attackers rent out the car’s IP address and bandwidth to third parties worldwide to bypass security measures, disguise illegal activities, and conduct digital ad fraud. Importantly, the malware does not affect critical vehicle safety systems such as steering, brakes, or engine control.
The attack is attributed to the Chinese hacking group MoYu, previously linked to large-scale Android device infections and known for the BADBOX campaign. This marks a dangerous escalation as cybercriminals shift from consumer electronics to automotive systems. Unlike concerns raised by the Israeli Defense Forces about Chinese-made vehicles like BYD and MG potentially leaking telemetry data, this threat involves aftermarket components that any driver can purchase and install independently.
Experts warn that these Android multimedia units often lack rigorous security controls, receive unverified updates, and may include SIM cards for independent internet access, increasing vulnerability. In contrast, original car systems using Android Auto or Apple CarPlay rely on the driver’s smartphone as the main processor, reducing attack surfaces. Kaspersky’s Asaf Hazan advises consumers to verify update sources, disable automatic updates from unknown servers, avoid unnecessary internet connections, prefer simpler mirroring units over full Android systems, and check pre-installed apps, especially in used vehicles.
This case highlights the growing cybersecurity risks posed by the blurred lines between cars, computers, and smartphones, emphasizing that threats now stem more from the supply chain of cheap aftermarket parts than from the car manufacturers themselves. While attention focuses on major automakers, the real privacy and network risks may lie in low-cost multimedia screens bought online for a few dozen dollars.