Cybersecurity researchers have discovered a new malware campaign targeting Android based vehicle head units by abusing built in software update mechanisms to deliver malicious payloads. Security firm Kaspersky identified the malware in June 2026 and said the threat is designed to deploy a multi stage downloader that enables ad fraud activities and the creation of a proxy botnet. Researchers described the campaign as the first documented case of malware found on a car head unit with an infection chain specifically designed for this type of automotive device. Dmitry Kalinin, security researcher at Kaspersky, said the malware spreads through legitimate update functionality integrated into Android based automotive head unit firmware developed by DoFun.
The activity has been linked with high confidence to MoYu Group, which was previously identified by HUMAN Satori Threat Intelligence and Research team as part of a broader ad fraud and residential proxy operation known as BADBOX. In July 2025, Google filed a lawsuit against 25 unnamed individuals or entities in China related to the alleged operation of the BADBOX botnet and its infrastructure. Researchers noted that Android powered car head units have become increasingly common in both factory installed vehicles and aftermarket upgrades, allowing standard Android applications and potentially malicious software to operate on these systems. These devices often include SIM card slots that provide internet connectivity for navigation services and software updates, making them an emerging target for malware campaigns. Kaspersky said threat delivery methods are becoming more diverse, including pre installed backdoors, compromised applications, and abuse of legitimate software update systems.
According to Kaspersky, the malware campaign specifically targeted the update mechanisms integrated into firmware used by multiple Android based head unit models powered by DoFun. Following responsible disclosure, the issue associated with the misuse of the software distribution process has been addressed. The attack begins with a legitimate system application called TWCore, identified as “com.tw.core”, which is responsible for collecting analytics and updating head unit software through APK files. The application uses an MQTT message broker hosted on the “cardoor[.]cn” subdomain to receive update instructions, after which APK files are downloaded to the “/push/apk/” location for installation. Threat actors are believed to have abused this update channel to deliver a previously unknown malware component called JarService while implementing techniques designed to avoid detection. The dropper launches a loader that sends implant information to an attacker controlled server through an HTTP POST request, after which the server provides a link to download the next stage payload.
The downloaded payload is deployed as a regular user application without a visible interface, allowing it to operate silently in the background. Kaspersky researchers found that the malware communicates with a command and control server every 90 minutes by sending information about the infected device and its configuration version through the “/cpc/api/task” endpoint. If the configuration requires an update, the server provides new C2 addresses and request paths. Otherwise, it sends integer command identifiers that the attackers refer to as productId. The malware stores command details as serialized JSON objects through the SharedPreferences API and supports multiple capabilities related to advertisements, data collection, and additional payload delivery. Its supported commands include returning stored values, modifying clipboard contents, sending HTTP requests, opening links through WebView with JavaScript execution capabilities, downloading additional code, opening browser URLs, and checking resource availability through ICMP ping requests.
Researchers found that attackers use the loadlib2 and http commands to deliver zhima, a reverse proxy module previously documented by Nokia Deepfield Emergency Response Team and distributed through certain IPTV applications installed on low cost Android TV boxes. Kaspersky said that despite efforts from cybersecurity researchers and law enforcement agencies to disrupt BADBOX related activity, associated operators continue targeting devices globally. The discovery highlights increasing security risks for connected automotive platforms as malware developers expand their focus beyond traditional computing devices.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.