VYPR
researchPublished Aug 21, 2026· Updated Aug 26, 2026· 6 sources

Android Malware Targets Automotive Head Units via Firmware Updates

Kaspersky researchers have identified a novel Android malware campaign specifically targeting automotive head units, marking the first documented instance of malware infecting these in-car systems through their firmware update mechanisms.

Kaspersky researchers have uncovered a new Android malware campaign that specifically targets automotive head units, a critical component in modern vehicles that integrates multimedia functions with vehicle controls. This discovery is significant as it represents the first documented instance of malware infecting car head units with an infection chain tailored to this specific device type. The malware, a multi-stage downloader, is designed for ad fraud and the creation of a proxy botnet, leveraging the head unit's internet connectivity.

The infection chain exploits a vulnerability within the firmware update process of DoFun brand head units. The TWCore application, a legitimate system app responsible for analytics and software updates, inadvertently facilitates the malware's installation. Attackers can manipulate the update mechanism, which uses MQTT messages to distribute APK files. A key element of the exploit is the installNotExists flag within the update process, which, when set to true, allows TWCore to install applications even if they are not part of the original firmware, thereby enabling the silent deployment of malicious software.

Once the TWCore app downloads and installs the malicious payload, the first stage, known as the JarService dropper, executes. This dropper is a small, UI-less application that decrypts embedded malicious code. It uses a simple XOR encryption with a shifting single-byte key to obfuscate its payload. The decrypted data contains serialized information about the next stage, including the entry point for further execution, effectively acting as a loader for the subsequent malicious components.

The second stage involves a malicious loader that uses reflection to execute further payloads. This loader communicates with a command-and-control (C2) server, sending implant information such as device details, app versions, and channel IDs. In return, the C2 server provides a URL to download the next stage of the malware. This stage-and-a-half approach allows attackers to maintain flexibility and potentially update their malicious infrastructure without needing to re-infect devices with the initial dropper.

The ultimate goal of this malware, as identified by Kaspersky, is to engage in ad fraud and establish a proxy botnet. By compromising the head unit, attackers can force the device to generate fraudulent ad revenue or use its internet connection as a proxy for other malicious activities. This is particularly concerning given the increasing connectivity and data capabilities of modern vehicles, which could be exploited for a wide range of illicit purposes.

Kaspersky attributes this campaign with high confidence to the MoYu Group, an actor previously linked to the BADBOX botnet. This attribution suggests a sophisticated and persistent threat actor capable of adapting their tactics to new targets and environments. The group's focus on ad fraud and botnet creation aligns with their known modus operandi.

Kaspersky solutions detect the various stages of this malware under several names, including HEUR:Trojan-Dropper.AndroidOS.Agent.vu, HEUR:Trojan-Downloader.AndroidOS.Agent.ov, HEUR:Trojan-Proxy.AndroidOS.Zhima.*, and HEUR:Trojan.AndroidOS.Vo1d.*. The vendor, DoFun, has been notified of the security issues and has reportedly implemented fixes to address the vulnerabilities in their head unit firmware, closing this specific infection vector.

This new report details that the malware, discovered by Kaspersky in June 2026, spreads via the built-in firmware updaters of DoFun vehicle head units. The malware operates as a multi-stage downloader, with its primary objectives being ad fraud and the establishment of a proxy botnet, effectively turning infected vehicles into compromised network nodes.

The new article provides further details on the MoYu Group's operation, identifying the malware as a multi-stage downloader for ad fraud and a proxy botnet. It specifically highlights the use of a legitimate system app, TWCore, to install malicious packages and attributes the discovery to Securelist researchers who observed the activity in June 2026. The report also notes that the vendor has since fixed the security issues exploited by the malware.

This new report from Kaspersky details the specific infection vector used by the Badbox malware, which leverages the built-in software updaters of Android-based car head units. The malware's functionality includes turning compromised devices into ad-fraud tools and proxy botnet nodes, marking the first documented instance of malware with an infection chain tailored to this specific automotive component.

This new report from Kaspersky provides further details on the malware targeting automotive head units, linking it to the BadBox botnet. The malware was found on an Android-powered aftermarket infotainment system from Chinese manufacturer DoFun, and threat actors exploited a vulnerability in the system's software update mechanism to deliver malicious applications. These applications function as droppers, loaders, and reverse-proxy loaders, with observed commands suggesting the primary goal is to build a proxy botnet.

This new report from Dark Reading reveals that the Android malware targeting automotive head units is specifically linked to a known click-fraud botnet. Threat actors are leveraging the legitimate update system not just for initial infection, but also to distribute further malicious payloads, expanding the scope of the campaign beyond what was initially understood.

Synthesized by Vypr AI
Android Malware Targets Automotive Head Units via Firmware Updates · VYPR