Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.
Key Highlights
- "The delivery methods for such malware are becoming highly varied – ranging from pre-installed backdoors to compromised IPTV applications," Kalinin said in a statement shared with The Hacker News.
- "If the configuration is outdated, the C2 server returns an updated configuration containing new C2 addresses and new paths for sending HTTP requests," Kaspersky said.
- 68"), allowing Kaspersky to retrieve seven distinct variants dating back to "3.
- "The malware spread through the built-in updaters of Android-based automotive head unit firmware," security researcher Dmitry Kalinin said.
- "Despite the efforts of cybersecurity experts and law enforcement agencies to shut down the BADBOX botnet, individual actors associated with it continue their malicious activities, infecting devices worldwide," Kalinin said.
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.
Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.
"The malware spread through the built-in updaters of Android-based automotive head unit firmware," security researcher Dmitry Kalinin said.
"This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.
" The activity has been attributed with high confidence to the MoYu Group, which was outed by the HUMAN Satori Threat Intelligence and Research team last year as part of a broader ad fraud and residential proxy scheme dubbed BADBOX.
In July 2025, Google filed a lawsuit against 25 unnamed individuals or entities in China for allegedly operating the BADBOX botnet and its infrastructure.
A car head unit is a central hub that combines multimedia functions with partial control over certain vehicle functions.
It can be factory-installed or fitted on older vehicles as part of an aftermarket upgrade.
Because Android-powered card head units have become popular across both aftermarket retrofits and factory-built vehicles, a huge chunk of the standard apps, and by extension, malware, can also run on them.
This, in turn, makes them an emerging target for bad actors, as they feature a SIM card slot that enables internet access for navigation and software updates.
"The delivery methods for such malware are becoming highly varied – ranging from pre-installed backdoors to compromised IPTV applications," Kalinin said in a statement shared with The Hacker News.
"In this researched case, we observed an even more sophisticated delivery method exploiting the legitimate software update functionality of a system app.
" Specifically, this involves distributing the malware via the update mechanisms built into the firmware of multiple models of Android-based head units powered by DoFun.
Following responsible disclosure, the issue driving the software distribution abuse has been addressed.
The starting point is a legitimate system app called TWCore ("com.
tw.
core"), which is designed to collect analytics and update the head unit's software in the form of APK files by making use of a MQTT message broker hosted on the "cardoor[.
]cn" subdomain.
The threat actors behind the campaign are said to have weaponized this update channel to deliver previously unknown malware directly to the head units using a dropper dubbed JarService, while taking steps to evade detection. The dropper is responsible for launching a loader that performs the following actions -
- Sends implant information to one of the attackers servers via an HTTP POST request
- Server responds with a link for downloading the next-stage payload ("144.217.243[.]201/vr34der34/dex3.68.png")
Originally reported by The Hacker News. TechVeb news desk.
Stay in the loop
Get the latest tech news and AI insights delivered to your inbox. No spam, unsubscribe anytime.
TechVeb Team
Your trusted source for the latest in technology, AI innovations, and digital trends. We bring you in-depth analysis, expert reviews, and comprehensive guides.
Learn more about us →More cybersecurity News
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal securit
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in ques
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-l


