Skip to content

SecurityWidely confirmed8 publishers3 min readPublished Updated

The firmware updater in the dashboard: car head units enrolled into a proxy botnet

Kaspersky says malware reached Android car head units through the vendor's own update mechanism, using a flag that installs apps the device never had. The payload has no interface at all.

The Watch · Security desk

How we use AISend a correction

What happened

  • While monitoring Android threats in June 2026, Kaspersky researchers discovered a new piece of Android malware.
  • The malware is a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet.
  • The malware spread through the built-in updaters of Android-based automotive head unit firmware.
  • Kaspersky says this is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.
  • Kaspersky attributes the activity, with high confidence, to the MoYu Group, an actor linked to the BADBOX botnet.

Why it matters

Kaspersky researchers say that while monitoring Android threats in June 2026 they found a multi-stage downloader whose ultimate purpose is ad fraud and the creation of a proxy botnet, and that it arrived on victim devices through the built-in updaters of Android-based automotive head unit firmware [6][1][2]. The company describes this as the first documented case of malware on a car head unit with an infection chain specific to that device class [3], which moves the dashboard from a theoretical target to an operational one.

The mechanism is mundane, which is the point. On the affected devices, a legitimate system application called TWCore handles analytics collection and software updates [7]. According to Kaspersky, an MQTT message broker hosted on the subdomain cardoor[.]cn sends TWCore messages describing APK files to download and install [8]. The message object carries a boolean field named installNotExists, which permits TWCore to install applications that were never on the device to begin with [9]. Downloads land in the updater's own external cache under push/apk/ [10]. Kaspersky's telemetry found previously unknown malware sitting at exactly those paths, and in every observed case the installer was an app with the package name com.tw.core, matching TWCore [11].

The first stage, JarService, is a small dropper with no user interface of any kind, decrypting payload data held as blocks XOR-encrypted with a single-byte key that shifts linearly from block to block [12]. What first drew the researchers' attention was that the malware installed like an ordinary user app yet made no attempt to look legitimate, having no UI at all, which suggested it was arriving without users' knowledge [13]. Put the two facts together: an updater authorised to install software that was not previously present [9], delivering a component with nothing to display [12], produces an infection with no visible moment in the cabin [18].

Kaspersky says the firmware design for DoFun head units enabled the distribution, and that after notification the vendor reported fixing the security issues [5]. Attribution, with high confidence, goes to the MoYu Group, an actor the company links to the BADBOX botnet [4]. Detections span dropper, downloader, proxy and Vo1d families [20], which is consistent with a supply chain being reused rather than a one-off experiment.

The economics are worth stating plainly. Kaspersky notes that a head unit typically holds nothing of value to an attacker, making botnet recruitment the likely scenario, much as with IoT devices [17]; combined with the stated goals of ad fraud and proxying [1], the asset being sold is the vehicle's network position, not the driver's data [19]. Head units often carry SIM slots and their own internet connectivity for navigation and updates [16], which is precisely what a proxy operator wants. Previous work on these systems focused on physical access and OS or component vulnerabilities [15]; this is the update path itself, on a device that combines media playback with partial control over vehicle functions and ships either from the factory or as an aftermarket upgrade [14].

What to watch: whether any independent party verifies DoFun's reported fix [5], and whether other Android head unit vendors ship equivalents of the installNotExists flag [9], since a remotely triggered silent install primitive is a distribution channel regardless of who is using it this month. Also watch for the same MoYu infrastructure appearing on other cheap Android hardware, given the stated BADBOX link [4]. For fleet operators, the practical question is whether anyone can enumerate the applications currently installed on their vehicles' head units at all.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence70
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence68

Perspective Coverage

8 publishers
Builder
Builder 36%
Operator
Operator 50%
Investor
Investor 14%
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The malware is a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet.

  2. [2]

    The malware spread through the built-in updaters of Android-based automotive head unit firmware.

  3. [3]

    Kaspersky says this is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.

    ReportedSupportedSource: Securelist (Kaspersky)4 sources— create a free account to open themView cited source

Sources

8 independent publishers whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · August 22, 2026

    Hackers infect Android car head units with proxy botnet malware
  2. helpnetsecurity.com

    1 article · August 24, 2026

    Android car head units infected with proxy botnet malware through built-in software updaters
  3. scworld.com

    1 article · August 21, 2026

    New malware targets Android car head units for ad fraud and botnet creation
  4. securelist.com

    1 article · August 21, 2026

    The invisible passenger in your car
  5. securityaffairs.com

    1 article · August 22, 2026

    Malware Hijacks Android Car Head Units
  6. securityweek.com

    1 article · August 25, 2026

    First Malware Built Specifically for Car Head Units Fuels Botnet
  7. thehackernews.com

    2 articles · August 22, 2026

    Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
  8. therecord.media

    1 article · August 24, 2026

    Hackers infecting Android car systems to build proxy botnet

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories