First documented attack on car head units
Security researchers have uncovered a new malware campaign that targets Android-based car systems, turning them into nodes of a proxy botnet. The discovery, detailed in a report by Kaspersky on Friday, marks the first documented case of malware infecting a car head unit through an attack specifically designed for this type of device.
Head units are the computers and screens built into cars that control navigation, music, Bluetooth, and other features. Previous attacks against such systems typically relied on physical access to the vehicle or vulnerabilities in the operating system.
How the infection works
The malware was found on head units made by DoFun, a Chinese automotive software and hardware provider. Kaspersky traced the infections to TWCore, a legitimate system application installed on DoFun devices that collects analytics and handles software updates. TWCore can also download and install new Android applications.
Attackers abused that functionality to push a malicious app called JarService onto affected devices. The attack requires no action from the driver — no clicking a link, visiting a malicious website, or installing anything manually. JarService has no visible user interface, making it difficult for drivers to notice their devices have been compromised.
Malware’s purpose: building a proxy botnet
JarService acts as a downloader for additional malicious code. The malware can display advertisements and generate fraudulent ad clicks, but Kaspersky said its ultimate purpose appears to be expanding a botnet — networks of infected devices that criminals can remotely use for cyberattacks, fraud, and traffic routing.
One of the malware modules observed by researchers turns infected head units into reverse proxies. This allows other people’s internet traffic to be routed through the infected device, making the activity appear to originate from the car’s internet connection. That’s a powerful tool for hiding criminal activity.
Kaspersky attributes campaign to MoYu Group
Kaspersky attributed the campaign with high confidence to MoYu Group, a threat actor linked to the BadBox malware operation. BadBox has previously compromised Android smartphones, tablets, streaming devices, and other internet-connected products.
“Despite efforts by cybersecurity professionals and law enforcement to shut down the BadBox botnet, individual actors linked to it continue their malicious activity, infecting devices worldwide,” Kaspersky researchers said.
BadBox has a history of pre-installed malware. In 2023, cybersecurity company HUMAN Security discovered more than 70,000 Android smartphones, connected TV boxes, and tablets from at least one Chinese manufacturer that had been shipped with malware linked to the operation.
BadBox’s persistence and evolution
In December 2024, German authorities disrupted the original BadBox botnet by cutting off communications between infected devices and the hackers’ command-and-control infrastructure. However, the hackers quickly resurfaced with an updated version of the botnet.
The FBI also warned last year that BadBox 2.0 was targeting internet-of-things devices, including TV streaming boxes, digital projectors, digital picture frames, and aftermarket vehicle infotainment systems. The new campaign against DoFun head units fits that pattern.
Kaspersky said it notified DoFun about the distribution scheme, and the vendor subsequently reported fixing the security issues. Still, the incident highlights a growing concern: as cars become more connected, they also become more attractive targets for cybercriminals. For related context, see our coverage of Android malware trends and botnet takedown efforts.
The discovery serves as a reminder that the internet of things extends to the vehicle in your driveway. Drivers should keep their car’s software updated and be aware that even legitimate-looking components can be exploited.