Kaspersky researchers identified a malware campaign designed specifically to target Android vehicle head units, marking the first documented infection chain tailored for modern automotive infotainment systems.

Vehicle manufacturers frequently install the Android operating system on these infotainment systems to customize interfaces and manage core media features. Because these devices feature persistent internet connections for navigation and system updates, they present an attractive target for digital attackers in the automotive sector.

Distribution Vector Across Vehicle Head Units

The threat actors distributed the multi-stage downloader using the firmware update mechanism of multiple device models powered by DoFun. The infection chain started through a legitimate system application named TWCore, which usually collects analytics and retrieves update instructions from vendor servers.

Attackers exploited this communication channel to deliver an unknown dropper named JarService to target systems. The software executed silently in the background as a user application without a visible user interface, making detection difficult for drivers during everyday vehicle operation.

Malicious Capabilities and Command Structure

Kaspersky discovered nine distinct commands implemented by the operators to manipulate infected devices. The malware was capable of executing ad fraud, displaying intrusive advertisements, and downloading additional malicious payloads directly onto the vehicle head units without requiring manual user authorization.

In addition, the malware collected technical telemetry from the host vehicle. The harvested information included display resolution, hardware model numbers, connected Wi-Fi network identifiers, and the device MAC address. This technical profile enabled the attackers to tailor secondary payloads to specific hardware configurations.

Attribution to MoYu Group and Botnet Infrastructure

Security analysts linked the malicious campaign to the MoYu Group, a threat entity associated with the BadBox botnet that previously infected streaming TV boxes. Furthermore, the administration panel of the operation shares code artifacts with residential proxy services like PXYEDGE and ProxyForU, indicating shared infrastructure across broader fraudulent monetization schemes.

“This malware has become the very first malicious application specifically targeting car head units through an infection chain explicitly tailored for these vehicle systems.”

Dmitry Kalinin, Security Researcher at Kaspersky

Industry Response and Automotive Security

Kaspersky notified DoFun regarding the compromised update mechanism, and the vendor stated that the vulnerability has been fixed. The incident highlights the growing need for specialized cybersecurity defenses across connected mobility ecosystems and embedded smart devices.

As modern automobiles rely increasingly on software-defined architectures and continuous network connectivity, securing supply chain software and third-party system components across vehicle head units remains critical for preventing unauthorized background operations and data harvesting.