Skip to content
New Android Malware Targets Car Head Units for Ad Fraud and Botnet Creation

New Android Malware Targets Car Head Units for Ad Fraud and Botnet Creation

First seen 21 Aug 2026, 15:18 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 22, 2026 at 14:48 UTC

A new Android malware has been discovered targeting automotive head units, specifically those using firmware from the Chinese company DoFun. This malware exploits a legitimate system application, TWCore, to deliver a malicious app named JarService, which has no user interface and operates unnoticed. The malware aims to create a botnet for ad fraud, allowing attackers to execute commands such as displaying ads and downloading additional malicious code. Kaspersky identified this threat in June 2026, marking the first documented case of malware delivered via an automatic firmware-update service for car head units. The malware is linked to the MoYu Group, previously associated with the BADBOX botnet. DoFun has been notified and has reportedly fixed the security issues. This incident highlights the vulnerabilities in automotive systems that utilize Android software.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 44d ago How this analysis works

Timeline

2026-06-01
Malware discovered targeting car head units
Kaspersky identified malware exploiting DoFun firmware to infect Android-based car head units.
Kaspersky
2026-08-21
Public disclosure of malware findings
Kaspersky and other sources published details about the malware's operation and impact on car head units.
Uk.Pcmag
2026-08-21
DoFun notified and security issues fixed
Following the discovery, DoFun reported that they have addressed the security vulnerabilities exploited by the malware.
Securelist

More articles in this cluster (20)

Following this threat?

Track MoYu Group, Badbox and DoFun in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed