Android Car Head Units Hacked by Proxy Botnet Malware
Hackers are exploiting a legitimate update app to infect Android car head units with malware, turning them into proxy botnet nodes or using them for ad fraud. The attack targets systems from Chinese provider DoFun.

Threat actors have compromised Android-based car head units through a sophisticated supply-chain attack, leveraging a seemingly legitimate device-update application to distribute malware. This malicious software enlists the affected infotainment systems into a proxy botnet or exploits them for advertising fraud. Security researchers at Kaspersky have identified the operation and attributed it to the MoYu group, a cybercriminal organization previously linked to the BadBox malware botnet. This marks the first documented instance of a malware infection chain specifically engineered for car head units.
The MoYu group's operation specifically targets systems provided by DoFun, a Chinese company specializing in automotive software and hardware, which is a subsidiary of Shenzhen Driving Control Technology Co., Ltd. DoFun supplies generic Android-based head units that serve as the central control for a vehicle's infotainment, navigation, and various system settings. In June 2026, Kaspersky researchers detected an unauthorized application package (APK) being downloaded from TWCore, a legitimate DoFun system app that receives commands via an MQTT server hosted at cardoor[.]cn. This clandestine app, identified as malware named JarService, operates without any user interface.
Upon execution, JarService decrypts and launches a secondary loader. This loader establishes communication with a command-and-control (C2) server, subsequently downloading another encrypted payload. The ultimate payload systematically reports crucial device information, including the model number, display resolution, Wi-Fi network name (SSID), and Media Access Control (MAC) address, while also retrieving instructions from the attackers. The malware is equipped to handle a range of commands, such as retrieving stored preferences, copying data to the clipboard, sending HTTP requests, opening specified URLs with JavaScript execution capabilities, and downloading/executing additional code modules. It also includes network diagnostic functions like traceroute.
Malware's Primary Objectives: Monetization and Espionage
Kaspersky's analysis indicates that the malware does not impede driving operations or critical vehicle control systems. Instead, its design appears focused on monetizing compromised devices through advertising fraud and repurposing internet-connected car head units into residential proxy nodes. Researchers observed the attackers primarily deploying a reverse-proxy module known as 'zhima,' which transforms the head unit into a proxy botnet node. Additionally, the malware was observed making web requests to engage in click-fraud activities.
The implications of such an attack are significant. While not directly affecting vehicle safety, the compromise of these interconnected systems raises concerns about data privacy and the potential for misuse of network resources. The ability to turn a vehicle's head unit into a proxy node can allow cybercriminals to mask their online activities, potentially engaging in illegal operations while routing traffic through unsuspecting users' vehicles. Ad fraud, while less severe, still represents a significant financial loss for advertisers and legitimate online content creators.
Kaspersky has informed DoFun of its findings. The Chinese company responded that the issue has been rectified. BleepingComputer has reached out to both DoFun and Shenzhen Driving Control Technology Co., Ltd. for further details regarding the initial compromise vector and will provide updates as more information becomes available. This incident underscores the growing cybersecurity risks associated with the increasing connectivity of vehicles and the potential for the automotive supply chain to become a target for sophisticated threat actors.
