Kaspersky has documented what it calls the first Android malware campaign built specifically for car head units, a family that hitches a ride on the devices’ legitimate update channel to plant ad fraud and proxy botnet code.
The malware targets infotainment firmware developed by DoFun, which powers aftermarket head units and some factory-built systems. Researchers found it distributed through the update mechanism of a system app called TWCore, which normally fetches analytics and APK updates over an MQTT broker hosted on a cardoor.cn subdomain. Attackers weaponized that channel to drop a loader named JarService, which installs a covert payload that reports to a command-and-control endpoint every 90 minutes.
Security researcher Dmitry Kalinin said this is the first documented case of malware on a car head unit with an infection chain specific to that device type. Kaspersky attributes the campaign with high confidence to the MoYu Group, the crew behind the BADBOX ad fraud and residential proxy scheme that Google sued over in July 2025.
Head units are an attractive target because they sit at the center of the cockpit, blend multimedia with partial vehicle control, and carry a SIM slot for navigation and updates. Kalinin noted that delivery methods keep evolving, from pre-installed backdoors to compromised apps, and that this case abused the software update functionality of a legitimate system component. The vendor addressed the flaw after responsible disclosure, and owners should install the latest firmware while treating head unit app sources with the same caution as smartphone downloads.