Android-based car head units are being targeted in a supply chain attack that abuses legitimate device update applications to install malware. The infected systems can be added to proxy botnets and used to conduct advertising fraud, according to Kaspersky researchers.
Kaspersky analyzed the malware campaign and attributed it to the MoYu threat group, an actor previously linked to the BadBox Android malware botnet.
Researchers say this is the first documented malware infection chain specifically designed to compromise Android automotive head units.
The MoYu operation targets systems supplied by DoFun, a Chinese automotive software and hardware provider owned by Shenzhen Driving Control Technology Co., Ltd.
DoFun develops automotive software, cloud services, and hardware, including generic Android-based car head units. These devices act as a central command system for in-car infotainment, navigation, and configuration features. DoFun Android-based head units are designed to integrate with connected vehicle systems.
In June, Kaspersky researchers discovered that malicious APK files were being downloaded through TWCore, a legitimate DoFun system application responsible for device updates. The application receives instructions from an MQTT server hosted on cardoor[.]C.N.
The downloaded application, which has no visible user interface, is a malware strain Kaspersky identified as JarService. After launching, JarService connects to a command-and-control (C2) server, decrypts and executes a second-stage loader, and downloads an additional encrypted payload.
The final payload periodically sends device details to the attackers, including the head unit model, screen resolution, Wi-Fi SSID, and MAC address. This information enables the malware operators to identify compromised devices and deliver commands.
The malware supports nine commands:
- return – Retrieves specified values from Android SharedPreferences storage.
- copy – Copies saved or downloaded content to the device clipboard.
- http – Sends HTTP GET or POST requests and saves part of the response.
- Web – Opens a URL in WebView and executes supplied JavaScript.
- Load library – Not fully implemented when Kaspersky published its report.
- Load library 2 – Downloads and executes additional code or modules.
- Load library 3 – Not fully implemented when Kaspersky published its report.
- Deep link – Opens a specified resource in a web browser.
- traceroute – Checks whether a specified host is reachable using ICMP ping.
Kaspersky said the malware does not appear to interfere with driving functions or critical vehicle control systems. Instead, the campaign appears focused on advertising fraud and monetizing internet-connected Android car head units as residential proxy nodes.

Source: Kaspersky
Researchers found that the operators primarily deployed a reverse proxy module called “zhima”. The module converts an infected car head unit into a proxy botnet node and can also generate fraudulent web requests for click fraud campaigns.
Kaspersky said it notified DoFun about the findings. The Chinese company responded that it had fixed the issue.
BleepingComputer has contacted both companies for additional information about the initial compromise method. This article will be updated if further details become available.
The overall prevention score can hide what happens after initial access. If an attacker uses valid credentials, your defenses can drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




