Kaspersky New Android Malware Targets Car Head Units for Ad Fraud and Botnet Creation
Article Content
- •Malware targets Android-based car head units developed by DoFun.
- •Infection occurs through legitimate firmware update mechanisms using TWCore.
- •The malware aims to create a botnet for ad fraud and has been linked to the MoYu Group.
A new Android malware has been discovered targeting automotive head units, specifically those using firmware from the Chinese company DoFun. This malware exploits a legitimate system application, TWCore, to deliver a malicious app named JarService, which has no user interface and operates unnoticed. The malware aims to create a botnet for ad fraud, allowing attackers to execute commands such as displaying ads and downloading additional malicious code. Kaspersky identified this threat in June 2026, marking the first documented case of malware delivered via an automatic firmware-update service for car head units. The malware is linked to the MoYu Group, previously associated with the BADBOX botnet. DoFun has been notified and has reportedly fixed the security issues. This incident highlights the vulnerabilities in automotive systems that utilize Android software.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (20)
Following this threat?
Track MoYu Group, Badbox and DoFun in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…