Kaspersky Finds First Malware Targeting Android Car Head Units

Kaspersky's Securelist has documented the first infection chain built for Android-based car head units: a DoFun firmware updater quietly installing a dropper that turns vehicles into ad-fraud and botnet nodes.
First documented infection chain for car head units
Kaspersky's Securelist team says that while monitoring Android threats in June 2026 it found new malware that installs like an ordinary app but has no interface at all — a strong hint that it reaches devices without their owners' knowledge. Investigation reconstructed the full chain: a multi-stage downloader built for ad fraud and the creation of a proxy botnet.
What stands out is the distribution path. The malware spread through the built-in updater of Android-based DoFun automotive head units. Kaspersky calls it the first documented case of malware on a car head unit with an infection chain specific to that class of device.
How it worked — and who is behind it
A legitimate system app, TWCore (com.tw.core), refreshes head-unit software by pulling APK files from an MQTT broker on cardoor[.]cn. An "installNotExists" flag let it install apps that were never on the device, and telemetry shows the malware arriving exactly this way, starting with a dropper named JarService. Kaspersky attributes the activity with high confidence to the MoYu Group, an actor linked to the BADBOX botnet, and says the vendor was notified and reported fixing the issues.
For drivers the lesson is mundane: keep firmware and head-unit software updated, and treat always-online car electronics as part of the attack surface.