Technology
Researchers uncover multi-stage malware targeting Android automotive head units
A campaign attributed to the MoYu Group exploited built-in update systems on DoFun vehicle head units to conduct ad fraud and operate proxy botnets.
The short version
- Security researchers discovered a multi-stage Android malware campaign targeting automotive head unit firmware via built-in system update mechanisms.
- The malware was deployed onto DoFun head units via a legitimate updater application, enabling unauthorized software downloads, ad fraud, and proxy botnet operations.
- Kaspersky attributed the activity with high confidence to the MoYu Group, an actor connected to the BADBOX botnet.
- The affected vendor reported fixing the underlying security vulnerabilities after being notified by researchers.
Key facts
- Kaspersky researchers identified new multi-stage Android malware targeting automotive head unit firmware in June 2026.[Hacker News]
- The campaign represents the first documented case of malware on a vehicle head unit featuring an infection chain engineered specifically for that device type.[Hacker News]
- Kaspersky attributed the activity with high confidence to the MoYu Group, a threat actor linked to the BADBOX botnet.[Hacker News]
- The malware was distributed through TWCore, a legitimate system app used for analytics and software updates on DoFun head units, using an MQTT broker.[Hacker News]
- The infection mechanism uses a UI-less dropper named JarService to load subsequent payloads capable of executing nine distinct commands for ad fraud, proxy routing, and additional code execution.[Hacker News]
- DoFun was notified of the distribution mechanism and stated that it resolved the security flaws.[Hacker News]
What remains uncertain
- The total number of automotive head units compromised by the campaign was not disclosed.[Hacker News]