Cybersecurity researchers have identified a new malware family specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky discovered this threat in June 2026, noting its primary goal is to deploy a multi-stage downloader for ad fraud and the establishment of a proxy botnet.
The malware propagates through the legitimate built-in updaters of Android-based automotive head unit firmware. This represents the first documented instance of malware found on a car head unit utilizing an infection chain specific to this type of device, exploiting its standard software update functionality.
This activity has been attributed with high confidence to the MoYu Group, previously identified by HUMAN Satori Threat Intelligence and Research as part of the BADBOX ad fraud and residential proxy scheme. In July 2025, Google filed a lawsuit against 25 unnamed entities in China for their alleged involvement in operating the BADBOX botnet and its infrastructure.
Android-powered car head units, popular in both aftermarket retrofits and factory-built vehicles, are becoming targets for malicious actors. These devices often include SIM card slots for internet access, making them susceptible to malware that can run alongside standard applications. The initial point of compromise involves a legitimate system app, TWCore, which handles analytics and software updates via an MQTT message broker.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new malware family targeting Android-based vehicle head units from DoFun has been discovered, spreading through the devices' built-in update mechanisms. This malware aims to facilitate ad fraud and create a proxy botnet, marking the first documented case of malware on car head units with a device-specific infection chain.