Cybersecurity researchers have uncovered a sophisticated supply-chain attack. That has infected Android-based car head units with proxy botnet malware, marking the. First documented instance of an infection chain. Specifically tailored for these automotive systems. Discovered by Kaspersky in June 2026, the operation, attributed to the notorious MoYu. Group, leverages a legitimate device-update application to. Spread malware, enlisting compromised vehicles into a proxy botnet for monetization and ad fraud. This guide covers Hackers infect Android car head units with proxy botnet malware in detail. This guide covers Hackers infect Android car head units with proxy botnet malware in detail. This guide covers Hackers infect Android car head units with proxy botnet malware in detail.
The attack targets head units manufactured by DoFun, a Chinese automotive software and hardware provider owned by Shenzhen Driving Control Technology Co., Ltd. DoFun supplies generic Android-based head units that serve as the central command hub for a car's infotainment, navigation, and settings. Kaspersky researchers identified a rogue APK file being downloaded from TWCore, a legitimate DoFun system app responsible for analytics and firmware updates. This malicious download was facilitated through an MQTT server hosted at cardoor[.]cn, exploiting a dangerous configuration flag named `installNotExists` within the update protocol, which allows the updater to install applications not already present on the device without user prompts.
Hackers infect Android car head units with proxy botnet malware: How Does the. Malware Infiltrate and Operate?
The initial malicious application, dubbed JarService, operates without a user interface and makes. No attempt to disguise itself, suggesting it. Is installed without the user's knowledge. Once launched, JarService decrypts and executes a second-stage loader. That establishes communication with a command-and-control (C2) server. This loader then downloads another encrypted payload, which periodically reports device information. Such as the model, display resolution, Wi-Fi SSID, and MAC address to the attackers.

The malware is equipped with a versatile set of nine commands, enabling various malicious activities. These include retrieving values from Android’s SharedPreferences storage, copying content to the clipboard, sending HTTP GET or POST requests, opening URLs in a WebView to execute JavaScript, and performing network reachability checks via ICMP ping. Crucially, the `loadlib2` command allows the malware to download and execute arbitrary code or additional modules. Researchers observed this command being used to deploy a reverse-proxy module named 'zhima'.
The 'zhima' module is central to the attackers' primary objectives: turning the infected. Car head units into residential proxy nodes. And facilitating ad fraud, specifically click-fraud activity. The MoYu group, identified by Kaspersky with high confidence, has a history of. Such operations, being closely associated with the. Infamous BadBox malware botnet and the IpMoYu residential-proxy service. The BadBox 2.0 botnet, which MoYu Group developed, has previously compromised over a million Android. Devices, often through supply-chain interventions or malicious apps. While the malware consumes some of the head unit's computing resources, potentially leading to slower infotainment systems or degraded internet speeds, Kasp Whether you are new to Hackers infect Android car head units with proxy botnet malware or already experienced, the sections below have you covered.ersky emphasizes that it does not interfere with driving or critical vehicle control systems.
What This Means for Tech Readers
This incident highlights a critical and evolving threat landscape. Where even specialized automotive systems are becoming targets for cybercriminals. For tech enthusiasts and everyday consumers, it underscores the inherent risks in the. Expanding ecosystem of connected devices. The fact that a legitimate update mechanism was exploited for malware delivery is. Particularly concerning, as it bypasses traditional user vigilance against suspicious downloads. It demonstrates that supply-chain attacks are not limited to enterprise software or consumer electronics. But now extend to the very vehicles we drive. The monetization strategy, focusing on residential proxy networks and ad fraud, also reveals. The diverse motives of threat actors, moving. Beyond direct data theft to leveraging device resources for illicit gains. This incident serves as a stark reminder that robust security practices. Including vigilant monitoring of software supply chains and rapid patching of vulnerabilities, are paramount for manufacturers. And for users, exercising caution with aftermarket installations and understanding the source of. Their device's firmware updates is increasingly vital.
What's Next in Automotive Cybersecurity?
The discovery of the MoYu group's campaign targeting Android car head units suggests. That automotive cybersecurity will become an increasingly critical area of focus. As vehicles become more connected and integrated with digital systems, they present new. Attack surfaces for cybercriminals. Manufacturers like DoFun, who have reportedly addressed the issue, will need to implement. More stringent security measures throughout their software. Development and update pipelines to prevent similar compromises. Future developments may include enhanced secure boot mechanisms, stricter code signing requirements. And continuous threat monitoring specifically tailored for automotive infotainment systems. , the broader cybersecurity community will likely see increased research into the vulnerabilities. Of embedded Android systems in vehicles, leading. To more sophisticated detection and prevention tools. Consumers, in turn, should anticipate more transparency from manufacturers regarding software security and. Update integrity in their connected cars. The ongoing battle against botnets like BadBox and groups like MoYu will continue. To push the boundaries of cybersecurity, demanding. Proactive and adaptive defenses across all connected platforms.
Related Resources
For more context, check our related article on TikTok to Pay Record $400 Million in Landmark Child Privacy Settlement with DOJ, related article on SynkLoader Malware Deploys Convincing Fake Lock Screens in Microsoft Teams Phishing Blitz, related article on Apple Calendar Gets an AI-Powered Overhaul in iOS 27 with. Smart Event Details and Enhanced Siri Integration.