Skip to content
Android Car Head-Unit Malware Linked to BadBox Uses Firmware Updates

Android Car Head-Unit Malware Linked to BadBox Uses Firmware Updates

Technadu August 21, 2026

A new malware campaign is targeting Android-based automotive head units. Rather than relying on a conventional malicious application download, the campaign abused the software-update functionality built into affected DoFun head units.

Kaspersky's Securelist researchers describe it as the first documented case of malware specifically built to infect such systems. The malware was discovered in June 2026 and attributed with high confidence to MoYu Group, a threat actor associated with the BadBox botnet.

According to Kaspersky, the infection was enabled by the design of the DoFun firmware and its legitimate TWCore application, which handles analytics and software updates. TWCore receives instructions from an MQTT broker hosted under cardoor[.]cn, including which APK files should be downloaded and installed.

Kaspersky found that a Boolean parameter named installNotExists could allow the application to install software that was not previously present on the device.

The infection proceeds through three stages. The first is JarService, a dropper without a user interface that decrypts and loads the component. A second-stage loader collects device information, communicates with a command-and-control (C2) server, and retrieves the final payload.

The third stage combines clicker and reverse-proxy loader functionality. It can execute commands including loadlib2 and http before deploying the zhima reverse-proxy module. Kaspersky said the resulting activity involves ad fraud and enrollment of infected devices into a proxy botnet .

Kaspersky's attribution connects the campaign to MoYu Group, an actor associated with BadBox. Separately, the Nokia Deepfield Emergency Response Team has identified zhima operating on Android TV set-top boxes, providing independent evidence of the module's use in proxy botnet activity.

Kaspersky also found links to residential proxy services PXYEDGE and ProxyForU, which it said reinforced the connection to MoYu Group.

Google's Android Automotive OS platform itself was not compromised. Kaspersky said it notified the vendor, which reported that the issues had been fixed.

For defenders and automotive manufacturers, the case highlights the security implications of software-update mechanisms in connected head units. Google's Android Automotive documentation emphasizes the importance of secure OTA mechanisms, verified boot, and isolation between Android applications and vehicle systems.

A June Include Security report said free smart TV apps embed a Bright Data SDK to build an AI web-scraping proxy network. In 2025, Google sued the operators behind the BadBox 2.0 Botnet that infected 10 million Android devices, and Android TV boxes were linked to botnet activity .

Extracted Entities

Attack Types (1)

Domains (1)

Malware (1)