Automotive head units as botnet proxies
# Automotive head units as botnet proxies
The MoYu Group has found a way to turn car dashboards into infrastructure for ad fraud. By exploiting a software update vulnerability in DoFun car head units, they've integrated these devices into the BadBox botnet. This isn't about stealing GPS coordinates or remotely braking cars; it’s about using the head unit as a proxy server.
This reveals a specific tradecraft shift toward "clean" IP addresses. Most security teams are tuned to flag traffic coming from known data centers or suspicious VPS providers. However, traffic originating from a consumer-grade IP—the kind associated with a home or a mobile connection linked to a vehicle—looks legitimate. Attackers use these devices to bypass geo-blocking and fraud detection systems because the traffic appears to be coming from a real person in a real location.
The claim here is that we are seeing the "residentialization" of botnets. The evidence is the targeting of embedded hardware like DoFun units, which operate on the periphery of traditional network monitoring. The implication is that the perimeter is no longer just the corporate firewall or the home router; it's any connected device with an internet gateway.
One might argue that a few thousand cars acting as proxies is a rounding error compared to the millions of compromised IoT devices already in the wild. But the objection fails because quality beats quantity in proxying. A smaller pool of high-reputation, consumer-grade IPs is far more valuable for sophisticated fraud than a massive army of flagged server IPs.
This rhymes with the Mirai botnet from 2016, which weaponized IoT devices to launch massive DDoS attacks. The parallel breaks down, however, in the intent. Mirai was built for volume and noise—crushing targets under a wave of traffic. BadBox is built for stealth and persistence. It doesn't want to knock you offline; it wants to pretend to be you while it siphons ad revenue or probes other networks.
It makes me wonder how many other "smart" vehicle components are currently acting as silent relays for traffic we can't see because we aren't looking at the car as a network node.
Moving from the driveway to the state level, Norway is dealing with the fallout of a large-scale DDoS attack targeting Vivicta, an IT partner for the Norwegian government. The attack knocked several public services offline, including ID-porten, the national identity verification service.
The focus usually stays on the victim—in this case, the government services—but the second-order effect is what matters here. When a central identity provider goes dark, the failure cascades. Citizens cannot access healthcare portals, tax records, or social benefits. The vulnerability wasn't in the government's own core infrastructure, but in the third-party partner providing the connectivity.
Government has been the second most targeted sector this week, with 129 stories recorded across our tracking. This suggests that attackers are increasingly targeting the "connective tissue" of governance—the MSPs and service providers—rather than attempting to breach hardened state databases directly.
Then there is the matter of attribution in the wake of US sanctions against Iranian MOIS-affiliated hackers. The US government has linked these actors to attacks on critical infrastructure, including a British power plant.
My confidence level in the attribution to MOIS for the broad campaign is moderate. The evidence—overlapping TTPs and infrastructure patterns—is consistent with previous Iranian operations. However, my confidence in attributing specific, individual intrusions at a single power plant to a specific government office remains low.
Fast attribution is almost always a political tool rather than a technical one. To move my confidence from low to high, I would need to see leaked internal communications or a direct link between the command-and-control infrastructure and a known state-funded facility that hasn't been compromised by a third party first. It is too easy to "false flag" an operation by using another nation's known toolsets.
The cost of this attribution gap is often seen in policy. We see 16 stories regarding law enforcement today, including these sanctions, but sanctions rarely deter state actors who operate with sovereign immunity.
Finally, there is a massive data dump involving multiple Fortune 500 companies. Just under 3.6 million employee records have appeared on the dark web. While the volume is high, the real risk here isn't the exposure of the data itself—which is likely an aggregation of various leaks—but the potential for highly targeted spear-phishing.
When you have a database of employees from the world's largest companies, you don't just have names and emails; you have an organizational chart for social engineering. An attacker doesn't need to break into a company if they can convince a mid-level manager that an email is coming from a colleague whose data they just bought.
This week's numbers highlight the sheer volume of noise we are filtering: 277 data breach stories in seven days, with 84 occurring today alone. In that environment, it's easy to miss the quiet signals.
The most uncomfortable scenario we aren't pricing in is the convergence of these trends. Imagine a state-sponsored actor using a BadBox-style automotive proxy network to launch spear-phishing attacks against Fortune 500 employees, using identity data stolen from a breach, all while appearing to originate from legitimate consumer IPs within the target's own city.
If the traffic looks like it's coming from a local Volvo in the company parking lot, your current geo-fencing and IP reputation tools are useless.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- FBI, CISA, and HHS Warn about Medusa Ransomware Targeting Over 500 Critical Infrastructure Organizations - CPO Magazine Google News Security
- Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access The Hacker News
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data The Hacker News
- Employee Databases from Multiple Fortune 500 Companies Affecting 3.6 Million Employees Listed on the Dark Web - CPO Magazine Google News Security
- Large DDoS attack knocks Norwegian public services offline The Record
- WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities SecurityWeek
- US sanctions Iranian cyber actors as UK discloses power plant attack The Record
- First Malware Built Specifically for Car Head Units Fuels Botnet SecurityWeek