Android car head unit malware delivered through a legitimate system updater has turned affected infotainment devices into proxy botnet nodes and tools for advertising fraud, according to Kaspersky research published on August 21 and reported by BleepingComputer on August 22. Kaspersky said the campaign targeted Android-based head units from Chinese automotive technology provider DoFun and represented the first documented infection chain built specifically for this class of vehicle device.

Kaspersky discovered the activity while monitoring Android threats in June 2026. The company attributed it with high confidence to the MoYu Group, an operator previously linked to the BADBOX botnet. The researchers did not publish an estimate of infected vehicles or identify affected countries, and they found no evidence that the malware interfered with driving or critical vehicle-control systems.

The infection began with TWCore, a legitimate system application that collects analytics and updates DoFun head unit software. TWCore received instructions through an MQTT broker at cardoor[.]cn and could install applications that were not already present. Kaspersky telemetry showed that TWCore installed a previously unknown interface-free APK called JarService, establishing a supply-chain delivery path that did not require the vehicle owner to install the app manually.

JarService decrypted and ran a second-stage loader, which reported implant information to attacker infrastructure and retrieved an encrypted third stage. That payload periodically sent the device model, display resolution, connected Wi-Fi network name and MAC address to command-and-control servers. Its supported functions included HTTP requests, clipboard access, opening web content, executing supplied JavaScript, checking host reachability and downloading additional code or modules.

Researchers observed the operators primarily deploy a reverse-proxy module called zhima, making the head unit an exit node through which third-party traffic could pass. They also saw commands that generated web requests for click-fraud activity. Kaspersky listed detection names and defanged network indicators in its report, including domains, IP addresses and hashes for the malicious stages and legitimate TWCore samples involved in delivery.

Kaspersky said it notified DoFun and that the vendor subsequently reported resolving the security issues, although public reporting did not describe the initial infrastructure compromise or provide a model-by-model remediation list. Owners and fleet operators using DoFun-based head units should obtain updates only through verified vendor channels, review unexpected network activity and seek vendor guidance on affected firmware. Network defenders can use Kaspersky's published indicators to inspect DNS, proxy and endpoint telemetry for related activity.