← Latest briefing

Technology

Researchers uncover multi-stage malware targeting Android automotive head units

A campaign attributed to the MoYu Group exploited built-in update systems on DoFun vehicle head units to conduct ad fraud and operate proxy botnets.

The short version

  • Security researchers discovered a multi-stage Android malware campaign targeting automotive head unit firmware via built-in system update mechanisms.
  • The malware was deployed onto DoFun head units via a legitimate updater application, enabling unauthorized software downloads, ad fraud, and proxy botnet operations.
  • Kaspersky attributed the activity with high confidence to the MoYu Group, an actor connected to the BADBOX botnet.
  • The affected vendor reported fixing the underlying security vulnerabilities after being notified by researchers.

Key facts

  • Kaspersky researchers identified new multi-stage Android malware targeting automotive head unit firmware in June 2026.[Hacker News]
  • The campaign represents the first documented case of malware on a vehicle head unit featuring an infection chain engineered specifically for that device type.[Hacker News]
  • Kaspersky attributed the activity with high confidence to the MoYu Group, a threat actor linked to the BADBOX botnet.[Hacker News]
  • The malware was distributed through TWCore, a legitimate system app used for analytics and software updates on DoFun head units, using an MQTT broker.[Hacker News]
  • The infection mechanism uses a UI-less dropper named JarService to load subsequent payloads capable of executing nine distinct commands for ad fraud, proxy routing, and additional code execution.[Hacker News]
  • DoFun was notified of the distribution mechanism and stated that it resolved the security flaws.[Hacker News]

What remains uncertain

  • The total number of automotive head units compromised by the campaign was not disclosed.[Hacker News]

Sources