Cybersecurity researchers at Kaspersky have identified a new malware family targeting Android-based vehicle head units from DoFun, marking the first documented infection chain tailored specifically for automotive systems.
Key Points
- The malware exploits legitimate firmware update mechanisms to deliver a multi-stage downloader for ad fraud and proxy botnet operations.
- Kaspersky discovered the threat in June 2026, attributing the campaign to the MoYu Group, the same entity behind the global BADBOX botnet.
- Attackers weaponized the TWCore system app to download the JarService dropper, which covertly executes malicious payloads in the background.
- The malware supports nine commands, including executing arbitrary JavaScript, performing HTTP requests, and downloading additional malicious modules like the "zhima" reverse proxy.
- The vulnerability was addressed following responsible disclosure, though the incident highlights ongoing risks from actors associated with the BADBOX infrastructure.