A new Android malware campaign has been discovered targeting car head units, the systems used for entertainment, navigation, and some vehicle-related functions. Kaspersky researchers identified the threat while monitoring Android attacks in June 2026. The malware is notable because it was delivered through the built-in software updater of affected Android-based automotive head units. Researchers described it as the first documented case of malware using an infection chain specifically designed for this type of vehicle system.
The affected head units were developed by DoFun and use Android-based firmware. These systems can be factory-installed or added later as aftermarket upgrades, making them increasingly common in cars. Because many Android applications can run on these head units, they can also become targets for Android malware. Some devices also have SIM connectivity, giving them internet access for navigation, updates, and other services, which creates another opportunity for attackers to abuse connected automotive systems.
The attack begins with a legitimate system application called TWCore, which handles analytics and software updates. Researchers found that attackers abused this trusted update mechanism to deliver a dropper called JarService to the head units. The malware was installed through the update process instead of requiring a user to manually install a suspicious application. This made the infection chain concerning because a trusted update function was used to deliver malicious software. This also reduced the visibility of the initial infection.
After JarService is delivered, it launches a component that collects information about the device and communicates with attacker-controlled infrastructure. The server can then provide a link to download the next stage of the malware. Researchers identified several payload versions by examining version numbers in the download path. The final malware runs as a normal user application but has no visible interface, allowing it to operate quietly in the background.
The malware communicates with command-and-control infrastructure and checks for instructions at regular intervals. Kaspersky found that it supports nine commands, including functions for making HTTP requests, opening links, changing clipboard contents, checking resource availability, and downloading additional code. Some commands can also open webpages inside a WebView and execute JavaScript. These capabilities give attackers control over how the infected head unit communicates and what additional malicious activity can be carried out.
Researchers found that the attackers were using commands called loadlib2 and http to download a module known as zhima. This module functions as a reverse proxy and has also been observed in inexpensive Android TV set-top boxes. Its use in this campaign shows that infected car head units can join a proxy botnet. The campaign also supports ad fraud, where infected systems can generate fraudulent advertising activity. This activity can also consume the device’s network resources.
Kaspersky attributed the campaign with high confidence to the MoYu Group, a threat actor associated with the BADBOX ecosystem. BADBOX has previously been linked to abuse of Android devices for ad fraud and residential proxy services. Researchers said that despite efforts by cybersecurity companies and law enforcement to disrupt BADBOX, associated actors continue to infect devices globally. The automotive campaign shows how these operators are expanding their focus beyond other consumer devices. The finding expands security concerns around connected vehicles and embedded Android systems.
Following responsible disclosure, the issue that enabled abuse of the legitimate update mechanism was addressed. The discovery is an important warning for the automotive industry as connected head units increasingly depend on software and internet services. The campaign demonstrates how trusted update systems can become powerful attack paths without proper protection. As cars adopt Android platforms, stronger security around firmware, apps, updates, and connected services will be essential.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news