Security1 distinct publisher3 min readUpdated
Kaspersky says malware reached Android car head units through the vendor's own update mechanism, using a flag that installs apps the device never had. The payload has no interface at all.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Kaspersky researchers say that while monitoring Android threats in June 2026 they found a multi-stage downloader whose ultimate purpose is ad fraud and the creation of a proxy botnet, and that it arrived on victim devices through the built-in updaters of Android-based automotive head unit firmware [1][2][3]. The company describes this as the first documented case of malware on a car head unit with an infection chain specific to that device class [4], which moves the dashboard from a theoretical target to an operational one.
The mechanism is mundane, which is the point. On the affected devices, a legitimate system application called TWCore handles analytics collection and software updates [7]. According to Kaspersky, an MQTT message broker hosted on the subdomain cardoor[.]cn sends TWCore messages describing APK files to download and install [8]. The message object carries a boolean field named installNotExists, which permits TWCore to install applications that were never on the device to begin with [9]. Downloads land in the updater's own external cache under push/apk/ [10]. Kaspersky's telemetry found previously unknown malware sitting at exactly those paths, and in every observed case the installer was an app with the package name com.tw.core, matching TWCore [11].
The first stage, JarService, is a small dropper with no user interface of any kind, decrypting payload data held as blocks XOR-encrypted with a single-byte key that shifts linearly from block to block [12]. What first drew the researchers' attention was that the malware installed like an ordinary user app yet made no attempt to look legitimate, having no UI at all, which suggested it was arriving without users' knowledge [13]. Put the two facts together: an updater authorised to install software that was not previously present [9], delivering a component with nothing to display [12], produces an infection with no visible moment in the cabin [19].
Kaspersky says the firmware design for DoFun head units enabled the distribution, and that after notification the vendor reported fixing the security issues [6]. Attribution, with high confidence, goes to the MoYu Group, an actor the company links to the BADBOX botnet [5]. Detections span dropper, downloader, proxy and Vo1d families [18], which is consistent with a supply chain being reused rather than a one-off experiment.
The economics are worth stating plainly. Kaspersky notes that a head unit typically holds nothing of value to an attacker, making botnet recruitment the likely scenario, much as with IoT devices [17]; combined with the stated goals of ad fraud and proxying [2], the asset being sold is the vehicle's network position, not the driver's data [20]. Head units often carry SIM slots and their own internet connectivity for navigation and updates [16], which is precisely what a proxy operator wants. Previous work on these systems focused on physical access and OS or component vulnerabilities [15]; this is the update path itself, on a device that combines media playback with partial control over vehicle functions and ships either from the factory or as an aftermarket upgrade [14].
What to watch: whether any independent party verifies DoFun's reported fix [6], and whether other Android head unit vendors ship equivalents of the installNotExists flag [9], since a remotely triggered silent install primitive is a distribution channel regardless of who is using it this month. Also watch for the same MoYu infrastructure appearing on other cheap Android hardware, given the stated BADBOX link [5]. For fleet operators, the practical question is whether anyone can enumerate the applications currently installed on their vehicles' head units at all.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
While monitoring Android threats in June 2026, Kaspersky researchers discovered a new piece of Android malware.
The malware is a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet.
The malware spread through the built-in updaters of Android-based automotive head unit firmware.
Kaspersky says this is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.
Kaspersky attributes the activity, with high confidence, to the MoYu Group, an actor linked to the BADBOX botnet.
The design of firmware for DoFun head units enabled attackers to distribute malware; Kaspersky notified the vendor about the distribution scheme, and the vendor subsequently reported fixing the security issues.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed single-vendor technical reconstruction
The report supplies concrete, checkable artefacts: the legitimate updater's name and package (com.tw.core), the MQTT broker subdomain, the push/apk/ staging path, the installNotExists flag, the stage-1 XOR block scheme and next-stage entry points, and four detection names. That is well above assertion-level evidence for the mechanism. It is capped by being one publisher reporting its own research, with the telemetry, the MoYu/BADBOX attribution and the vendor fix all unverified externally and without counts, model lists, or an advisory identifier.
Confirmed in the wild, scale unquantified
Adoption of the attack is real but unsized: vendor telemetry places the malware on actual devices with the updater as installer in every observed case, and seven distinct payload variants were retrievable from the distribution infrastructure, which implies an operating campaign. Against that, no infected-device counts, geographies, affected vehicle models, or firmware versions are given, and the only remediation datapoint is the vendor's own report of a fix, so real-world footprint cannot be graded higher.
Measured write-up, novelty framing runs ahead of the numbers
The technical body is restrained and specific, and the source is explicit that a head unit holds little of value so the target is network position rather than data — the opposite of dramatising a car-hacking scenario. The modest positive gap comes from the 'first documented case' superlative and the headline framing of vehicles enrolled into a botnet, neither of which is accompanied by prevalence figures, affected model lists, or independent confirmation of the fix.
Security-vendor research with product-visible payoff
The sole source is a commercial anti-malware vendor's own research blog, and the post lists the vendor's detection names for the threats it describes, which is a direct product-demonstration benefit. The vendor also has a reputational interest in the novelty claim of a first documented head-unit infection chain. Offsetting factors are the coordinated-disclosure behaviour toward DoFun and the concrete, independently checkable technical indicators, which are not typical of purely promotional content.
Coherent mechanism, single-source and unsized
Confidence is moderate: the infection chain is internally consistent and unusually specific about the legitimate component abused, and the derived readings about a silent install and network-position monetisation follow directly from the reported facts. It is held down by having exactly one publisher, no independent corroboration of telemetry or attribution, no quantified exposure, and a fix known only from the vendor's own report.
security
ToxicPanda 2.0 Widens From 16 Apps to 140, and From Overlays to ADB Shell3 distinct publishers
build
Geofencing beats GPS polling on power, then loses to the OEM battery optimiser1 distinct publisher
security
Cavern's DNS Coin-Flip: When Google Apps Script Becomes Rotatable C2 Plumbing1 distinct publisher
security
The EncroChat "national security secret" was exploit code sitting on GitHub1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026