Security — August 24, 2026 at 12:59 pm

Kaspersky discovers a malware campaign targeting car head units

by

In June 2026, Kaspersky uncovered a novel Android malware targeting vehicle Head Units – systems combining multimedia and, in some cases, car control functions. Taking the form of a stealthy multi-stage downloader, this campaign marks the first documented case of malware infecting a car’s head unit through an infection chain explicitly tailored for these vehicle systems.

malware

The goal is to deploy multi-stage malware that would enable carrying out ad fraud and other malicious activities. Kaspersky researchers believe this activity may be attributed to the MoYu Group, a threat actor closely tied to the infamous BadBox botnet.

Vehicle head units as the target

Car head units can be factory-installed or added on older vehicles post-purchase. Because head unit manufacturers frequently utilize the Android operating system to easily customize interfaces and add vital system components, the majority of standard Android applications – and Android malware – can run on these devices. While head units rarely store sensitive personal data, they usually have SIM card slots and have constant internet access for

Compromised updates as the infection vector

The malware was distributed via the update mechanisms built into the firmware of multiple models of Android-based head units powered by DoFun. Kaspersky has notified the vendor regarding this software distribution abuse. According to DoFun, the issue has been fixed.

The infection chain originates from a legitimate system app called TWCore, which is originally responsible for collecting analytics and updating the head unit’s software. TWCore would get instructions from the manufacturer’s server detailing which apps on the head units needed to be installed or updated. Attackers leveraged this channel to deliver previously unknown malware directly to the head units using a dropper called JarService. The infection process was complex and multi-stage, designed to evade detection. The malware got installed as a regular user application but lacked a user interface, and it operated in the background without the user noticing.

Kaspersky found that attackers had implemented nine distinct commands capable of displaying unwanted advertisements, executing ad fraud, and downloading additional malicious modules. Attackers also received device information including display resolution, device model, connected Wi-Fi network identifier, and the MAC address of the device.

Links to MoYu Group

Kaspersky uncovered links of this campaign to the MoYu Group, which is affiliated with the BadBox botnet, by comparing this campaign to previous attacks on TV set-top boxes. Furthermore, the administration panel of this botnet shares artifacts like embedded URLs in webpage code with residential proxy service websites PXYEDGE and ProxyForU. The BadBox botnet is a large-scale network of hijacked Android devices – streaming TV boxes, phones, and tablets – that come pre-infected with malware straight from the factory. Attackers use these hidden backdoors to commit ad fraud, steal data, and turn home networks into illegal proxy traffic relays.

For more information, see the post on Securelist.