AUTO-UPDATED

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Cybersecurity researchers at Kaspersky have identified a new malware family targeting Android-based vehicle head units from DoFun, marking the first documented infection chain tailored specifically for automotive systems.

Key Points

  • The malware exploits legitimate firmware update mechanisms to deliver a multi-stage downloader for ad fraud and proxy botnet operations.
  • Kaspersky discovered the threat in June 2026, attributing the campaign to the MoYu Group, the same entity behind the global BADBOX botnet.
  • Attackers weaponized the TWCore system app to download the JarService dropper, which covertly executes malicious payloads in the background.
  • The malware supports nine commands, including executing arbitrary JavaScript, performing HTTP requests, and downloading additional malicious modules like the "zhima" reverse proxy.
  • The vulnerability was addressed following responsible disclosure, though the incident highlights ongoing risks from actors associated with the BADBOX infrastructure.

Why it Matters

This discovery marks a significant escalation in automotive cybersecurity, as attackers have successfully weaponized essential vehicle software update channels to compromise hardware. It underscores the growing vulnerability of connected vehicle platforms and the need for manufacturers to implement more rigorous security protocols for aftermarket and factory-installed infotainment systems.
Internet Published by info@thehackernews.com (The Hacker News)
Read original