Skip to main content
LiMP VPN
All news

Android Malware Targets Car Head Units via Firmware Updates

Android Malware Targets Car Head Units via Firmware Updates

In short: In June 2026, Kaspersky documented the first Android malware purpose-built for automotive infotainment systems. The malicious program enters devices through the OTA firmware update channel of DoFun-based head units, collects device telemetry, and enlists infected units in a residential proxy botnet. CNews and Securelist covered the discovery on 21 August 2026; DoFun released a patch after being notified by Kaspersky researchers.

The First Malware Built Specifically for Car Head Units

Until now, automotive infotainment systems sat largely outside the crosshairs of serious threat actors: the market is fragmented, devices are heterogeneous, and monetising an attack is non-trivial. Kaspersky changed that picture by documenting the first multi-stage infection chain designed specifically for Android-based head units running DoFun firmware — one of the most prevalent manufacturers of budget in-car multimedia systems.

DoFun-based head units are common across Russia, CIS countries, and many other markets. Affordable Android head units with navigation, streaming, and voice assistant features have been installed in millions of vehicles, and their owners rarely consider them targets for cyber threats.

Three Infection Stages: From a Trusted Update to a Botnet Node

The attack unfolds in three stages, exploiting user trust in the official firmware update mechanism:

  • Stage 1 — JarService dropper. The malicious module disguises itself as the legitimate system application TWCore, which handles analytics and OTA updates. Through an MQTT broker on the subdomain cardoor[.]cn, attackers send a command to install an APK. Because TWCore operates with system-level privileges, the user receives no notification.
  • Stage 2 — second-stage loader. Decrypts an XOR-encrypted payload and establishes a connection with command-and-control (C2) servers, transmitting device telemetry: screen resolution, device model, Wi-Fi SSID, and MAC address.
  • Stage 3 — zhima module. Deploys a reverse proxy, turning the head unit into a node in a residential proxy botnet. A click-fraud component runs simultaneously in the background, clicking on advertisements to generate revenue for the attackers.

In total, the attackers implemented nine separate commands — from downloading additional modules to directly controlling the infected device.

Who Is Behind the Attack: MoYu Group and the BADBOX Botnet

Kaspersky analysts linked the campaign to MoYu Group, a threat actor affiliated with the BADBOX botnet. BADBOX was previously observed conducting mass infections of inexpensive Android devices out of the box — budget smartphones, tablets, and media players shipped with malware pre-installed in the firmware.

The attack's network infrastructure overlaps with PXYEDGE and ProxyForU — commercial residential proxy providers. The monetisation model is clear: infected devices are leased as proxy nodes through which third parties route and anonymise their traffic.

What This Means for the Owner of an Infected Head Unit

The threat may seem technical and distant from personal data. The consequences, however, are concrete:

  • Network data leakage. The MAC address and Wi-Fi SSID of your home network or frequently visited locations are transmitted to attackers' servers. Combined with other data sources, this enables detailed movement profiling.
  • Your internet connection weaponised. The head unit becomes a proxy botnet node: third-party requests — potentially illegal ones — pass through your connection. From an external observer's perspective, you are the source of those requests.
  • Resource drain. Click-fraud and proxy activity consume mobile data if the head unit uses a SIM card, and degrade device performance.
  • A foothold for further attacks. With a persistent presence on a networked device, attackers can push additional modules: keyloggers, password stealers, or surveillance tools.

How to Protect Yourself

DoFun published a fix for affected devices after being notified by Kaspersky. If you own an Android head unit running DoFun firmware, take these steps:

  • Update the firmware manually from the manufacturer's official website — not through the built-in OTA mechanism, which was the compromised channel.
  • Review the installed applications list in the device settings. System APKs with no visible interface that you do not recognise are worth investigating.
  • Restrict the head unit's network access. If navigation and multimedia work without an internet connection, disable persistent Wi-Fi or place the device on an isolated guest network segment.
  • Use a VPN on your smartphone when tethering it to the head unit. When your phone acts as a hotspot, encryption at the phone level protects transmitted data from interception. Learn more on the LiMP VPN features page.
  • Monitor for traffic anomalies. A sudden spike in data consumption from a device is the first sign of proxy activity.

Embedded malware shares a common pattern — infection through a trusted update channel. The same scheme was previously applied against smart TVs and Android set-top boxes. The LiMP VPN privacy blog covers emerging threats and practical protection steps.

Sources

Android Malware Targets Car Head Units via Firmware Updates