In June 2026, Kaspersky uncovered a novel Android malware targeting vehicle Head Units – systems combining multimedia and, in some cases, car control functions. Taking the form of a stealthy multi-stage downloader, this campaign marks the first documented case of malware infecting a car’s head unit through an infection chain explicitly tailored for these vehicle systems. The goal is to deploy multi-stage malware that would enable carrying out ad fraud and other malicious activities. Kaspersky researchers believe this activity may be attributed to the MoYu Group, a threat actor closely tied to the infamous BadBox botnet.
Vehicle head units as the target
Car head units can be factory-installed or added on older vehicles post-purchase. Because head unit manufacturers frequently utilize the Android operating system to easily customize interfaces and add vital system components, the majority of standard Android applications – and Android malware – can run on these devices. While head units rarely store sensitive personal data, they usually have SIM card slots and have constant internet access for navigation and software updates, which makes them a potential target for attackers.
Compromised updates as the infection vector
The malware was distributed via the update mechanisms built into the firmware of multiple models of Android-based head units powered by DoFun. Kaspersky has notified the vendor regarding this software distribution abuse. According to DoFun, the issue has been fixed.
The infection chain originates from a legitimate system app called TWCore, which is originally responsible for collecting analytics and updating the head unit’s software. TWCore would get instructions from the manufacturer’s server detailing which apps on the head units needed to be installed or updated. Attackers leveraged this channel to deliver previously unknown malware directly to the head units using a dropper called JarService. The infection process was complex and multi-stage, designed to evade detection. The malware got installed as a regular user application but lacked a user interface, and it operated in the background without the user noticing.
Kaspersky found that attackers had implemented nine distinct commands capable of displaying unwanted advertisements, executing ad fraud, and downloading additional malicious modules. Attackers also received device information including display resolution, device model, connected Wi-Fi network identifier, and the MAC address of the device.
Links to MoYu Group
Kaspersky uncovered links of this campaign to the MoYu Group, which is affiliated with the BadBox botnet, by comparing this campaign to previous attacks on TV set-top boxes. Furthermore, the administration panel of this botnet shares artifacts like embedded URLs in webpage code with residential proxy service websites PXYEDGE and ProxyForU. The BadBox botnet is a large-scale network of hijacked Android devices – streaming TV boxes, phones, and tablets – that come pre-infected with malware straight from the factory. Attackers use these hidden backdoors to commit ad fraud, steal data, and turn home networks into illegal proxy traffic relays.
“Despite the efforts of cybersecurity experts and law enforcement agencies to shut down the BadBox botnet, individual actors associated with it continue their malicious activities, infecting devices worldwide. The delivery methods for such malware are becoming highly varied – ranging from pre-installed backdoors to compromised IPTV applications. In this researched case, we observed an even more sophisticated delivery method exploiting the legitimate software update functionality of a system app. Malicious actors are actively conquering new platforms. This malware has become the very first malicious application specifically targeting car head units through an infection chain explicitly tailored for these vehicle systems. This servs as a warning that modern automotive platforms urgently require robust protection against malware,” comments Dmitry Kalinin, security researcher at Kaspersky.
For more information, see the post on Securelist.
About Kaspersky Threat Research
The Threat Research team is a leading authority in protecting against cyberthreats. By actively engaging in both threat analysis and technology creation, our TR experts ensure that Kaspersky’s cybersecurity solutions are deeply informed and exceptionally potent, providing critical threat intelligence and robust security to our clients and the broader community.