Skip to main content

Kaspersky discovers a malware campaign targeting car head units

August 21, 2026

In June 2026, Kaspersky uncovered a novel Android malware targeting vehicle Head Units – systems combining multimedia and, in some cases, car control functions. Taking the form of a stealthy multi-stage downloader, this campaign marks the first documented case of malware infecting a car’s head unit through an infection chain explicitly tailored for these vehicle systems. The goal is to deploy multi-stage malware that would enable carrying out ad fraud and other malicious activities. Kaspersky researchers believe this activity may be attributed to the MoYu Group, a threat actor closely tied to the infamous BadBox botnet.

Vehicle head units as the target

Car head units can be factory-installed or added on older vehicles post-purchase. Because head unit manufacturers frequently utilize the Android operating system to easily customize interfaces and add vital system components, the majority of standard Android applications – and Android malware – can run on these devices. While head units rarely store sensitive personal data, they usually have SIM card slots and have constant internet access for navigation and software updates, which makes them a potential target for attackers.

Compromised updates as the infection vector

The malware was distributed via the update mechanisms built into the firmware of multiple models of Android-based head units powered by DoFun. Kaspersky has notified the vendor regarding this software distribution abuse. According to DoFun, the issue has been fixed.

The infection chain originates from a legitimate system app called TWCore, which is originally responsible for collecting analytics and updating the head unit’s software. TWCore would get instructions from the manufacturer’s server detailing which apps on the head units needed to be installed or updated. Attackers leveraged this channel to deliver previously unknown malware directly to the head units using a dropper called JarService. The infection process was complex and multi-stage, designed to evade detection. The malware got installed as a regular user application but lacked a user interface, and it operated in the background without the user noticing.

Kaspersky found that attackers had implemented nine distinct commands capable of displaying unwanted advertisements, executing ad fraud, and downloading additional malicious modules. Attackers also received device information including display resolution, device model, connected Wi-Fi network identifier, and the MAC address of the device.

Links to MoYu Group

Kaspersky uncovered links of this campaign to the MoYu Group, which is affiliated with the BadBox botnet, by comparing this campaign to previous attacks on TV set-top boxes. Furthermore, the administration panel of this botnet shares artifacts like embedded URLs in webpage code with residential proxy service websites PXYEDGE and ProxyForU. The BadBox botnet is a large-scale network of hijacked Android devices – streaming TV boxes, phones, and tablets – that come pre-infected with malware straight from the factory. Attackers use these hidden backdoors to commit ad fraud, steal data, and turn home networks into illegal proxy traffic relays.

Despite the efforts of cybersecurity experts and law enforcement agencies to shut down the BadBox botnet, individual actors associated with it continue their malicious activities, infecting devices worldwide. The delivery methods for such malware are becoming highly varied – ranging from pre-installed backdoors to compromised IPTV applications. In this researched case, we observed an even more sophisticated delivery method exploiting the legitimate software update functionality of a system app. Malicious actors are actively conquering new platforms. This malware has become the very first malicious application specifically targeting car head units through an infection chain explicitly tailored for these vehicle systems. This servs as a warning that modern automotive platforms urgently require robust protection against malware,” comments Dmitry Kalinin, security researcher at Kaspersky.

For more information, see the post on Securelist.

About Kaspersky Threat Research

The Threat Research team is a leading authority in protecting against cyberthreats. By actively engaging in both threat analysis and technology creation, our TR experts ensure that Kaspersky’s cybersecurity solutions are deeply informed and exceptionally potent, providing critical threat intelligence and robust security to our clients and the broader community.

Kaspersky discovers a malware campaign targeting car head units

In June 2026, Kaspersky uncovered a novel Android malware targeting vehicle Head Units – systems combining multimedia and, in some cases, car control functions. Taking the form of a stealthy multi-stage downloader, this campaign marks the first documented case of malware infecting a car’s head unit through an infection chain explicitly tailored for these vehicle systems. The goal is to deploy multi-stage malware that would enable carrying out ad fraud and other malicious activities. Kaspersky researchers believe this activity may be attributed to the MoYu Group, a threat actor closely tied to the infamous BadBox botnet.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases