Android Car Head Unit Malware
Your car's infotainment system might be running more than just navigation and music. Security researchers just found the first-ever malware designed specifically to infect Android-based car head units. And it's using a legitimate software update feature to get in.
Kaspersky discovered the threat in June 2026. The malware targets head unit firmware developed by DoFun. Its end goal? To serve as a multi-stage downloader that enables ad fraud and builds a proxy botnet.
The activity is linked to the MoYu Group, which was outed last year as part of the BADBOX ad fraud and residential proxy scheme. Google even filed a lawsuit against 25 unnamed individuals in China for allegedly operating the BADBOX botnet.
Let me break down what's happening and what it means for car owners.
Summary of Important Points
- First-of-its-kind malware infection found that targets automotive head units
- Found attacks on DoFun head units with an Android firmware
- The infections spread via app updates to genuine applications
- Used to conduct ad click fraud and generate botnets
- Developed by BADBOX/MoYu group
- Found by Kaspersky in June 2026
What Is Car Head Unit?
Car head unit is the central hub of your vehicle. It combines multimedia functions with partial control over certain vehicle functions. It can be factory-installed or fitted on older vehicles as an aftermarket upgrade.
Android-powered head units have become popular in both aftermarket retrofits and factory-built vehicles. That means a huge chunk of standard Android apps and malware, can also run on them.
Why They're a Target:
Car head units have a SIM card slot that enables internet access for navigation and software updates. That makes them an emerging target for bad actors.
How the Malware Spreads
The malware spreads through the built-in updaters of DoFun automotive head unit firmware. It's a sophisticated delivery method.
The Delivery Method:
"The delivery methods for such malware are becoming highly varied, ranging from pre-installed backdoors to compromised IPTV applications," said Dmitry Kalinin of Kaspersky. "In this researched case, we observed an even more sophisticated delivery method exploiting the legitimate software update functionality of a system app."
The TWCore System App:
The starting point is a legitimate system app called TWCore ("com.tw.core"). It is used to gather analytics and update the head unit software. It involves the use of MQTT message broker that runs under the “cardoor[.]cn” sub-domain. The APK file is saved at a certain location.
How Attackers Weaponized It:
The threat actors weaponized this update channel. They delivered previously unknown malware directly to head units using a dropper called JarService. They took steps to evade detection.
The Infection Chain
The Android car head unit malware follows a multi-stage process:
Stage 1: Dropper Deployment
The JarService dropper launches a loader that sends implant information to an attacker server via HTTP POST.
Stage 2: Payload Download
The server responds with a link for downloading the next-stage payload.
Stage 3: Multiple Variants
The payload name includes a version number. Kaspersky retrieved seven distinct variants just by trying other version numbers.
Stage 4: Malware Deployment
The attack chain ends with the deployment of the malware as a regular user application. There is no user interface, and it works secretly in the background.
Stage 5: C2 Communication
It's configured to send a POST request to the C2 endpoint every 90 minutes by default. It sends information about the infected device and its configuration version.
The Commands
The malware supports nine commands that allow attackers to:
- Set clipboard contents
- Make HTTP requests
- Execute JavaScript in WebView
- Download and execute code
- Open URLs in the browser
- Check resource availability
The Zhima Module:
The threat actors use two commands to download "zhima," a reverse proxy module. This module was documented by Nokia Deepfield last month and has been delivered via IPTV apps on cheap Android TV boxes.
The BADBOX Connection
The Android car head unit malware is linked to the BADBOX botnet. Despite efforts by cybersecurity experts and law enforcement to shut it down, individual actors associated with it continue their malicious activities.
The Warning:
"This malware has become the very first malicious application specifically targeting car head units through an infection chain explicitly tailored for these vehicle systems," Kalinin said.
"This serves as a warning that modern automotive platforms urgently require robust protection against malware."
Things to Know for Car Owners
The Threat:
- Malware can be spread via software updates
- Infected head units can be utilized to commit fraud
- They can be turned into parts of a botnet of proxies
- Attackers gain access to device information
The Warning Signs:
- Unusual actions performed by head units
- Unexpected ads
- Slowdowns and battery issues
- Unusual network activity
The Bottom Line
The Android car head unit malware is the first documented case of malware specifically targeting automotive head units. It uses legitimate update channels to deliver ad fraud and proxy botnet malware.
Key Facts:
- First ever malware for car head unit
- Takes aim at DoFun Android-based firmware
- Employs updates of TWCore system applications
- Helps carry out advertising fraud and operates proxy botnet
- Created by BADBOX/MoYu group
Car owners should pay attention to this emerging threat. Automotive platforms urgently require robust protection against malware.
The Android car head unit malware is a warning that modern vehicles are becoming connected in ways that create new security risks. Stay informed. Stay secure.
FAQ Section
What is the Android car head unit malware?
It's the first documented malware specifically targeting Android-based vehicle head units. It uses legitimate firmware updates to deliver ad fraud and proxy botnet malware.
How does it spread?
It spreads through the built-in updaters of DoFun automotive head unit firmware. Attackers weaponized a legitimate system app called TWCore.
Who is behind it?
The activity is attributed to the MoYu Group, which is linked to the BADBOX botnet operation.
What is the effect of the malware?
It helps commit ad fraud and builds proxy botnet. Moreover, it gathers device data and is capable of downloading malicious modules.
What measures must car owners take?
They should be aware of this new threat. They should keep an eye on any strange activity from their car head unit. Update your car software regularly.