← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

New Android Car Head Unit Malware Uses Built-In Updaters for Ad Fraud and Botnets

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Malware targets Android-based DoFun vehicle head units.
  • Spreads via legitimate built-in software updaters.
  • Used for ad fraud and proxy botnet creation.
  • Attributed to MoYu Group, linked to BADBOX botnet.

Discovery of New Automotive Malware

Cybersecurity researchers have identified a new malware family specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky discovered this threat in June 2026, noting its primary goal is to deploy a multi-stage downloader for ad fraud and the establishment of a proxy botnet.

Unique Infection Vector

The malware propagates through the legitimate built-in updaters of Android-based automotive head unit firmware. This represents the first documented instance of malware found on a car head unit utilizing an infection chain specific to this type of device, exploiting its standard software update functionality.

Attribution and Broader Scheme

This activity has been attributed with high confidence to the MoYu Group, previously identified by HUMAN Satori Threat Intelligence and Research as part of the BADBOX ad fraud and residential proxy scheme. In July 2025, Google filed a lawsuit against 25 unnamed entities in China for their alleged involvement in operating the BADBOX botnet and its infrastructure.

Vulnerability of Car Head Units

Android-powered car head units, popular in both aftermarket retrofits and factory-built vehicles, are becoming targets for malicious actors. These devices often include SIM card slots for internet access, making them susceptible to malware that can run alongside standard applications. The initial point of compromise involves a legitimate system app, TWCore, which handles analytics and software updates via an MQTT message broker.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~21 min · 18 stories · Aug 21

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A new malware family targeting Android-based vehicle head units from DoFun has been discovered, spreading through the devices' built-in update mechanisms. This malware aims to facilitate ad fraud and create a proxy botnet, marking the first documented case of malware on car head units with a device-specific infection chain.