A supply-chain attack is compromising Android-based car head units through a legitimate device update application, installing malware that turns the systems into proxy botnet nodes or tools for advertising fraud. Researchers at Kaspersky identified the operation and linked it to the MoYu group, a threat actor previously connected to the BadBox malware botnet. According to the researchers, this marks the first documented malware infection chain specifically designed to target car head units.
The attackers are focusing on products from DoFun, a Chinese automotive software and hardware provider owned by Shenzhen Driving Control Technology Co., Ltd. DoFun sells generic Android head units, which function as the central interface for a vehicle’s infotainment, navigation, and setting controls. In June, Kaspersky analysts discovered a rogue APK file being downloaded from a legitimate DoFun system application named TWCore, which receives instructions through an MQTT server hosted at a domain tied to the company.
The unknown app, which has no user interface, is a piece of malware called JarService. Upon launch, the malware decrypts and executes a second-stage loader that establishes contact with a command-and-control server and downloads another encrypted payload. This final payload periodically reports device information such as the model, display resolution, Wi-Fi SSID, and MAC address, while also retrieving commands from the attackers.
Kaspersky found that the malware does not interfere with driving functions or critical vehicle control systems. Instead, it appears to be designed for monetization purposes, primarily loading a reverse-proxy module named "zhima" that transforms the head unit into a proxy botnet node. Additionally, the malware made web requests for click-fraud activity, indicating a dual purpose of generating revenue through both proxy services and ad fraud.
The researchers state that they notified DoFun of their findings, and the Chinese firm responded that it had resolved the problem. BleepingComputer has reached out to both companies regarding the initial compromise vector and has said it will update its article with any response received. For U.S. consumers, this highlights a growing concern as Android head units become more common in aftermarket vehicle installations, making them a new target for botnet operations that can consume data and bandwidth without the owner’s knowledge.
More cybersecurity news from TechManNews.






