← All stories
● Covered by 5 sources · 5 reportsMedium impact5 negative

New Android Car Head Unit Malware Uses Built-In Updaters for Ad Fraud and Botnets

🔄 Updated 38d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Malware targets Android-based DoFun vehicle head units.
  • Spreads via legitimate built-in software updaters.
  • Used for ad fraud and proxy botnet creation.
  • Attributed to MoYu Group, linked to BADBOX botnet.
  • MoYu's operation targets DoFun systems.
  • DoFun is owned by Shenzhen Driving Control Technology Co., Ltd.
  • Kaspersky found a rogue APK from DoFun's TWCore app in June.
  • TWCore receives instructions via an MQTT server at cardoor[.]cn.
  • The malware is named JarService.
  • Malware is a multi-stage downloader.
  • Malware has no user interface.
  • Kaspersky detects threats as HEUR:Trojan-Dropper.AndroidOS.Agent.vu, HEUR:Trojan-Downloader.AndroidOS.Agent.ov, HEUR:Trojan-Proxy.AndroidOS.Zhima.*, and HEUR:Trojan.AndroidOS.Vo1d.*.
  • Kaspersky notified DoFun about the distribution scheme.
  • DoFun reported fixing the security issues.
  • DoFun infotainment systems are widely used in China and other APAC countries.
  • Malware supports nine commands.
  • Malware operators can display ads.

Discovery of New Automotive Malware

Cybersecurity researchers have identified a new malware family specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky discovered this threat in June 2026, noting its primary goal is to deploy a multi-stage downloader for ad fraud and the establishment of a proxy botnet.

Unique Infection Vector

The malware propagates through the legitimate built-in updaters of Android-based automotive head unit firmware. This represents the first documented instance of malware found on a car head unit utilizing an infection chain specific to this type of device, exploiting its standard software update functionality.

Attribution and Broader Scheme

This activity has been attributed with high confidence to the MoYu Group, previously identified by HUMAN Satori Threat Intelligence and Research as part of the BADBOX ad fraud and residential proxy scheme. In July 2025, Google filed a lawsuit against 25 unnamed entities in China for their alleged involvement in operating the BADBOX botnet and its infrastructure.

Vulnerability of Car Head Units

Android-powered car head units, popular in both aftermarket retrofits and factory-built vehicles, are becoming targets for malicious actors. These devices often include SIM card slots for internet access, making them susceptible to malware that can run alongside standard applications. The initial point of compromise involves a legitimate system app, TWCore, which handles analytics and software updates via an MQTT message broker.

Updates

🕒 2026-08-25 · new reporting from SecurityWeek
  • DoFun infotainment systems are widely used in China and other APAC countries.
  • Malware supports nine commands.
  • Malware operators can display ads.
🕒 2026-08-24 · new reporting from The Record
  • Kaspersky notified DoFun about the distribution scheme.
  • DoFun reported fixing the security issues.
🕒 2026-08-23 · new reporting from Hacker News Front Page
  • Malware is a multi-stage downloader.
  • Malware has no user interface.
  • Kaspersky detects threats as HEUR:Trojan-Dropper.AndroidOS.Agent.vu, HEUR:Trojan-Downloader.AndroidOS.Agent.ov, HEUR:Trojan-Proxy.AndroidOS.Zhima.*, and HEUR:Trojan.AndroidOS.Vo1d.*.
🕒 2026-08-22 · new reporting from BleepingComputer
  • MoYu's operation targets DoFun systems.
  • DoFun is owned by Shenzhen Driving Control Technology Co., Ltd.
  • Kaspersky found a rogue APK from DoFun's TWCore app in June.
  • TWCore receives instructions via an MQTT server at cardoor[.]cn.
  • The malware is named JarService.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Kaspersky researchers discovered the first malware specifically designed for car head units, found on Android-powered aftermarket infotainment systems from DoFun. This malware exploits a software update vulnerability to deliver malicious Android applications, and is linked to the MoYu Group, operators of the BadBox botnet, indicating an expansion of BadBox's target devices beyond typical Android devices.

Kaspersky researchers identified new malware infecting Android-based car head units from Chinese provider DoFun, turning them into a botnet. This marks the first documented instance of malware specifically designed to infect car head units, enabling threat actors to route internet traffic through compromised vehicles and display ads.

Security researchers discovered new Android malware, attributed to the MoYu Group, that infects automotive head unit firmware through built-in updaters. This malware creates a proxy botnet and performs ad fraud, marking the first documented case of malware specifically targeting car head units through this infection vector.

Kaspersky researchers discovered a supply-chain attack targeting Android-based car head units, using a legitimate update app to spread malware for a proxy botnet or ad fraud. The MoYu group, known for BadBox malware, is attributed to this operation, which marks the first documented malware infection chain specifically for car head units. This development indicates a new vector for botnet and ad fraud activities, impacting automotive software providers and potentially users of affected head units.

A new malware family targeting Android-based vehicle head units from DoFun has been discovered, spreading through the devices' built-in update mechanisms. This malware aims to facilitate ad fraud and create a proxy botnet, marking the first documented case of malware on car head units with a device-specific infection chain.