Hackers infect Android car head units with proxy botnet malware

A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud.

Kaspersky researchers analyzed the malware and attributed the operation to the MoYu group, a threat actor previously associated with the BadBox malware botnet.

The researchers note that this is the first documented case of a malware infection chain specifically created for the targeted car head unit.

MoYu’s operation targets systems from DoFun, a Chinese automotive software and hardware provider owned by Shenzhen Driving Control Technology Co., Ltd.

DoFun is an automotive software, cloud services, and hardware provider that sells generic Android-based head units, which act as the command center for a car’s infotainment, navigation, and settings systems.

In June, Kaspersky researchers found a rogue APK file being downloaded from a legitimate DoFun system app, TWCore, which receives instructions through an MQTT server hosted at cardoor[.]cn.

The unknown app has no interface and is a piece of malware called JarService. When launched, the malware decrypts and executes a second-stage loader that establishes communication with a command-and-control (C2) server and downloads another encrypted payload.

The final payload periodically reports device information such as the model, display resolution, Wi-Fi SSID, and MAC address, and retrieves commands from the attackers.

The malware supports the following nine commands:

Kaspersky says the malware does not interfere with driving or critical vehicle control systems, and appears designed for advertising fraud and turning internet-connected car head units into residential proxy nodes for monetization purposes.

Researchers discovered that the operator primarily loaded a reverse-proxy module named ‘zhima,’ which turns the head unit into a proxy botnet node, and also made web requests for click-fraud activity.

Kaspersky says it notified DoFun of its findings, and the Chinese firm replied that it resolved the problem.

BleepingComputer has contacted both companies with questions about the initial compromise vector, and we will update the article with the information once received.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

NetNut proxy network disrupted, 2 million infected devices cut off

ToxicPanda Android malware uses VPN permissions to block Google Play

New Manic Android malware can exfiltrate data through nearby devices

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

I think the complete computerization went too far when even the headlights of your car can get hacked …

I think this is all after market Chinese units. That’s a very small audience I would think. And who’s connecting their aftermarket unit to the internet. That’s another bill. Seems almost very targeted to a specific group.

tverweij is correct. It has been the very wrong and particularly stupid decision to maximise digitalisation in everything, especially tin can move at 100mph, while you sit in them. This seems to be harmless, but I am waiting for some real collapse that will bring all traffic in a huge city to a halt. But… people are stupid and feel miserable about themselves, so they work in a job they do not like, do make money they buy things they do not need to impress people they do not like. Enjoy the future! It is on its way!

“tverweij is correct. It has been the very wrong and particularly stupid decision to maximise digitalisation in everything, especially tin can move at 100mph, while you sit in them. This seems to be harmless, but I am waiting for some real collapse that will bring all traffic in a huge city to a halt. But… people are stupid and feel miserable about themselves, so they work in a job they do not like, do make money they buy things they do not need to impress people they do not like. Enjoy the future! It is on its way!” It’s been here for 40 years, it’s just getting worse, all of which has been predicted prior to each step. Have you not read the lyrics to “21st Century Digital Boy”? It was written in the late 80’s and recorded in 1990.

I suggest burning the internet before it’s too late.

Hundreds of leaked AWS keys give full control over corporate accounts

Microsoft patches max severity code execution, privilege escalation flaws

Microsoft rolls out Classic Outlook theme for New Outlook users

Protect yourself from data brokers, scammers, and the next data breach with digital identities.

Certighost CVE is new. The privilege behind it isn’t. Discover where yours is hiding.

See how AI is reshaping email attacks. Download the 2026 Kaseya Email Security Report.

Discover how least agency keeps your AI tools capable, controlled, and secure.

Signature-based prevention fell to 50%. See what your controls still stop.

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.