Cybersecurity researchers have identified a new malware family specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky discovered this threat in June 2026, noting its primary goal is to deploy a multi-stage downloader for ad fraud and the establishment of a proxy botnet.
The malware propagates through the legitimate built-in updaters of Android-based automotive head unit firmware. This represents the first documented instance of malware found on a car head unit utilizing an infection chain specific to this type of device, exploiting its standard software update functionality.
This activity has been attributed with high confidence to the MoYu Group, previously identified by HUMAN Satori Threat Intelligence and Research as part of the BADBOX ad fraud and residential proxy scheme. In July 2025, Google filed a lawsuit against 25 unnamed entities in China for their alleged involvement in operating the BADBOX botnet and its infrastructure.
Android-powered car head units, popular in both aftermarket retrofits and factory-built vehicles, are becoming targets for malicious actors. These devices often include SIM card slots for internet access, making them susceptible to malware that can run alongside standard applications. The initial point of compromise involves a legitimate system app, TWCore, which handles analytics and software updates via an MQTT message broker.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Kaspersky researchers discovered the first malware specifically designed for car head units, found on Android-powered aftermarket infotainment systems from DoFun. This malware exploits a software update vulnerability to deliver malicious Android applications, and is linked to the MoYu Group, operators of the BadBox botnet, indicating an expansion of BadBox's target devices beyond typical Android devices.
Kaspersky researchers identified new malware infecting Android-based car head units from Chinese provider DoFun, turning them into a botnet. This marks the first documented instance of malware specifically designed to infect car head units, enabling threat actors to route internet traffic through compromised vehicles and display ads.
Security researchers discovered new Android malware, attributed to the MoYu Group, that infects automotive head unit firmware through built-in updaters. This malware creates a proxy botnet and performs ad fraud, marking the first documented case of malware specifically targeting car head units through this infection vector.
Kaspersky researchers discovered a supply-chain attack targeting Android-based car head units, using a legitimate update app to spread malware for a proxy botnet or ad fraud. The MoYu group, known for BadBox malware, is attributed to this operation, which marks the first documented malware infection chain specifically for car head units. This development indicates a new vector for botnet and ad fraud activities, impacting automotive software providers and potentially users of affected head units.
A new malware family targeting Android-based vehicle head units from DoFun has been discovered, spreading through the devices' built-in update mechanisms. This malware aims to facilitate ad fraud and create a proxy botnet, marking the first documented case of malware on car head units with a device-specific infection chain.