Published · 2d agoSecurity3 min read
The firmware updater in the dashboard: car head units enrolled into a proxy botnet
Kaspersky says malware reached Android car head units through the vendor's own update mechanism, using a flag that installs apps the device never had. The payload has no interface at all.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- While monitoring Android threats in June 2026, Kaspersky researchers discovered a new piece of Android malware.
- The malware is a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet.
- The malware spread through the built-in updaters of Android-based automotive head unit firmware.
- Kaspersky says this is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.
- Kaspersky attributes the activity, with high confidence, to the MoYu Group, an actor linked to the BADBOX botnet.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Kaspersky researchers say that while monitoring Android threats in June 2026 they found a multi-stage downloader whose ultimate purpose is ad fraud and the creation of a proxy botnet, and that it arrived on victim devices through the built-in updaters of Android-based automotive head unit firmware [1][2][3]. The company describes this as the first documented case of malware on a car head unit with an infection chain specific to that device class [4], which moves the dashboard from a theoretical target to an operational one.
The mechanism is mundane, which is the point. On the affected devices, a legitimate system application called TWCore handles analytics collection and software updates [7]. According to Kaspersky, an MQTT message broker hosted on the subdomain cardoor[.]cn sends TWCore messages describing APK files to download and install [8]. The message object carries a boolean field named installNotExists, which permits TWCore to install applications that were never on the device to begin with [9]. Downloads land in the updater's own external cache under push/apk/ [10]. Kaspersky's telemetry found previously unknown malware sitting at exactly those paths, and in every observed case the installer was an app with the package name com.tw.core, matching TWCore [11].
The first stage, JarService, is a small dropper with no user interface of any kind, decrypting payload data held as blocks XOR-encrypted with a single-byte key that shifts linearly from block to block [12]. What first drew the researchers' attention was that the malware installed like an ordinary user app yet made no attempt to look legitimate, having no UI at all, which suggested it was arriving without users' knowledge [13]. Put the two facts together: an updater authorised to install software that was not previously present [9], delivering a component with nothing to display [12], produces an infection with no visible moment in the cabin [19].
Kaspersky says the firmware design for DoFun head units enabled the distribution, and that after notification the vendor reported fixing the security issues [6]. Attribution, with high confidence, goes to the MoYu Group, an actor the company links to the BADBOX botnet [5]. Detections span dropper, downloader, proxy and Vo1d families [18], which is consistent with a supply chain being reused rather than a one-off experiment.
The economics are worth stating plainly. Kaspersky notes that a head unit typically holds nothing of value to an attacker, making botnet recruitment the likely scenario, much as with IoT devices [17]; combined with the stated goals of ad fraud and proxying [2], the asset being sold is the vehicle's network position, not the driver's data [20]. Head units often carry SIM slots and their own internet connectivity for navigation and updates [16], which is precisely what a proxy operator wants. Previous work on these systems focused on physical access and OS or component vulnerabilities [15]; this is the update path itself, on a device that combines media playback with partial control over vehicle functions and ships either from the factory or as an aftermarket upgrade [14].
What to watch: whether any independent party verifies DoFun's reported fix [6], and whether other Android head unit vendors ship equivalents of the installNotExists flag [9], since a remotely triggered silent install primitive is a distribution channel regardless of who is using it this month. Also watch for the same MoYu infrastructure appearing on other cheap Android hardware, given the stated BADBOX link [5]. For fleet operators, the practical question is whether anyone can enumerate the applications currently installed on their vehicles' head units at all.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
While monitoring Android threats in June 2026, Kaspersky researchers discovered a new piece of Android malware.
- [2]
The malware is a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet.
ReportedView cited source - [3]
The malware spread through the built-in updaters of Android-based automotive head unit firmware.
ReportedView cited source - [4]
Kaspersky says this is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.
- [5]
Kaspersky attributes the activity, with high confidence, to the MoYu Group, an actor linked to the BADBOX botnet.
- [6]
The design of firmware for DoFun head units enabled attackers to distribute malware; Kaspersky notified the vendor about the distribution scheme, and the vendor subsequently reported fixing the security issues.
ReportedView cited source
Sources & coverage · 5 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securelist.comDmitry Kalinin2d agoThe invisible passenger in your car
- scworld.comSC StaffyesterdayNew malware targets Android car head units for ad fraud and botnet creation



