SecurityWidely confirmed8 publishers3 min readPublished Updated
The firmware updater in the dashboard: car head units enrolled into a proxy botnet
Kaspersky says malware reached Android car head units through the vendor's own update mechanism, using a flag that installs apps the device never had. The payload has no interface at all.
The Watch · Security desk
What happened
- While monitoring Android threats in June 2026, Kaspersky researchers discovered a new piece of Android malware.
- The malware is a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet.
- The malware spread through the built-in updaters of Android-based automotive head unit firmware.
- Kaspersky says this is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.
- Kaspersky attributes the activity, with high confidence, to the MoYu Group, an actor linked to the BADBOX botnet.
Why it matters
Kaspersky researchers say that while monitoring Android threats in June 2026 they found a multi-stage downloader whose ultimate purpose is ad fraud and the creation of a proxy botnet, and that it arrived on victim devices through the built-in updaters of Android-based automotive head unit firmware [6][1][2]. The company describes this as the first documented case of malware on a car head unit with an infection chain specific to that device class [3], which moves the dashboard from a theoretical target to an operational one.
The mechanism is mundane, which is the point. On the affected devices, a legitimate system application called TWCore handles analytics collection and software updates [7]. According to Kaspersky, an MQTT message broker hosted on the subdomain cardoor[.]cn sends TWCore messages describing APK files to download and install [8]. The message object carries a boolean field named installNotExists, which permits TWCore to install applications that were never on the device to begin with [9]. Downloads land in the updater's own external cache under push/apk/ [10]. Kaspersky's telemetry found previously unknown malware sitting at exactly those paths, and in every observed case the installer was an app with the package name com.tw.core, matching TWCore [11].
The first stage, JarService, is a small dropper with no user interface of any kind, decrypting payload data held as blocks XOR-encrypted with a single-byte key that shifts linearly from block to block [12]. What first drew the researchers' attention was that the malware installed like an ordinary user app yet made no attempt to look legitimate, having no UI at all, which suggested it was arriving without users' knowledge [13]. Put the two facts together: an updater authorised to install software that was not previously present [9], delivering a component with nothing to display [12], produces an infection with no visible moment in the cabin [18].
Kaspersky says the firmware design for DoFun head units enabled the distribution, and that after notification the vendor reported fixing the security issues [5]. Attribution, with high confidence, goes to the MoYu Group, an actor the company links to the BADBOX botnet [4]. Detections span dropper, downloader, proxy and Vo1d families [20], which is consistent with a supply chain being reused rather than a one-off experiment.
The economics are worth stating plainly. Kaspersky notes that a head unit typically holds nothing of value to an attacker, making botnet recruitment the likely scenario, much as with IoT devices [17]; combined with the stated goals of ad fraud and proxying [1], the asset being sold is the vehicle's network position, not the driver's data [19]. Head units often carry SIM slots and their own internet connectivity for navigation and updates [16], which is precisely what a proxy operator wants. Previous work on these systems focused on physical access and OS or component vulnerabilities [15]; this is the update path itself, on a device that combines media playback with partial control over vehicle functions and ships either from the factory or as an aftermarket upgrade [14].
What to watch: whether any independent party verifies DoFun's reported fix [5], and whether other Android head unit vendors ship equivalents of the installNotExists flag [9], since a remotely triggered silent install primitive is a distribution channel regardless of who is using it this month. Also watch for the same MoYu infrastructure appearing on other cheap Android hardware, given the stated BADBOX link [4]. For fleet operators, the practical question is whether anyone can enumerate the applications currently installed on their vehicles' head units at all.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence68
Perspective Coverage
8 publishers- Builder
- Builder 36%
- Operator
- Operator 50%
- Investor
- Investor 14%
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The malware is a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet.
- [2]
The malware spread through the built-in updaters of Android-based automotive head unit firmware.
- [3]
Kaspersky says this is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.
ReportedSupportedSource: Securelist (Kaspersky)4 sources— create a free account to open themView cited source - [4]
Kaspersky attributes the activity, with high confidence, to the MoYu Group, an actor linked to the BADBOX botnet.
ReportedSupportedSource: Securelist (Kaspersky)4 sources— create a free account to open themView cited source - [5]
The design of firmware for DoFun head units enabled attackers to distribute malware; Kaspersky notified the vendor about the distribution scheme, and the vendor subsequently reported fixing the security issues.
- [6]
While monitoring Android threats in June 2026, Kaspersky researchers discovered a new piece of Android malware.
ReportedSupportedSource: Securelist (Kaspersky)3 sources— create a free account to open themView cited source - [7]
TWCore is a legitimate system application responsible for collecting analytics data and updating the head unit software.
- [8]
An MQTT message broker hosted on the subdomain cardoor[.]cn sends a message containing information about the APK files that need to be downloaded and installed on the head unit.
- [9]
The object describing the update message includes an installNotExists field, a boolean flag that allows TWCore to install apps that were not originally present on the device.
- [10]
The APK file is downloaded to the TWCore external cache directory under push/apk/ for installation.
- [11]
Kaspersky telemetry revealed previously unknown malware at those file paths, and in every observed case the malware was installed by an app with the package name com.tw.core, which matches the TWCore package name.
- [12]
Stage 1, JarService, is a small dropper app with no UI of any kind; it decrypts data stored as encrypted blocks within the Trojan's code, each block XOR-encrypted with a single-byte key that shifts linearly from block to block.
- [13]
The malware installed like an ordinary user app yet made no attempt to disguise itself as legitimate software and had no user interface at all, which led researchers to suspect it was reaching users' devices without their knowledge.
- [14]
A head unit combines multimedia functions with partial control over certain vehicle functions, and may come as factory equipment or as an aftermarket upgrade.
- [15]
The main attack vectors previously covered for head units are compromise via physical access and vulnerabilities in the head unit's OS or components.
- [16]
Head units often include SIM card slots and can connect to the internet, enabling features such as navigation and software updates.
- [17]
Kaspersky notes that a head unit typically holds nothing of value to an attacker, so one of the more likely attack scenarios using classic Android malware is infecting the device to recruit it into a botnet, similar to attacks on IoT devices.
ReportedSupportedSource: Securelist (Kaspersky)2 sources— create a free account to open themView cited source - [18]
Because the updater is authorised to install applications that were not previously present and the delivered first-stage dropper has no user interface, the infection presents no visible install moment to the vehicle occupant.
- [19]
The monetised asset in this campaign is the vehicle's network position rather than data held on the head unit.
- [20]
Kaspersky detection names for the described threats include HEUR:Trojan-Dropper.AndroidOS.Agent.vu, HEUR:Trojan-Downloader.AndroidOS.Agent.ov, HEUR:Trojan-Proxy.AndroidOS.Zhima.* and HEUR:Trojan.AndroidOS.Vo1d.*.
Sources
8 independent publishers whose own reporting we read for this story.
- bleepingcomputer.comHackers infect Android car head units with proxy botnet malware
1 article · August 22, 2026
- helpnetsecurity.comAndroid car head units infected with proxy botnet malware through built-in software updaters
1 article · August 24, 2026
- scworld.comNew malware targets Android car head units for ad fraud and botnet creation
1 article · August 21, 2026
- securelist.comThe invisible passenger in your car
1 article · August 21, 2026
- securityaffairs.comMalware Hijacks Android Car Head Units
1 article · August 22, 2026
- securityweek.comFirst Malware Built Specifically for Car Head Units Fuels Botnet
1 article · August 25, 2026
- thehackernews.comAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
2 articles · August 22, 2026
- therecord.mediaHackers infecting Android car systems to build proxy botnet
1 article · August 24, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Android MalwareFollow
- Automotive cybersecurityFollow
- Software Supply Chain AttacksFollow
- Proxy BotnetsFollow
- Ad FraudFollow