Kaspersky has uncovered what it described as the first documented malware campaign designed specifically to infect Android-based car head units through an attack chain tailored to vehicle systems.
The cybersecurity company detected the campaign in June 2026. The malware was distributed through software-update mechanisms built into several Android head units powered by DoFun.
Kaspersky notified the vendor, which said the issue had been fixed.
The attack exploited TWCore, a legitimate system application used for analytics and software updates. Normally, the app receives instructions from the manufacturer’s server specifying which applications should be installed or updated.
Attackers used that channel to distribute previously unknown malware through a dropper called JarService. The malicious software was installed as a normal application but had no user interface, allowing it to run in the background without alerting the driver.
Kaspersky identified nine commands supported by the malware. These included displaying unwanted advertisements, conducting ad fraud and downloading additional malicious modules.
The attackers could also collect information including the head unit’s model and display resolution, the identifier of the connected Wi-Fi network and the device’s MAC address.
Kaspersky linked the campaign to the MoYu Group, a threat actor associated with the BadBox botnet, after finding similarities with earlier attacks involving Android TV set-top boxes and related infrastructure.
BadBox has previously been associated with compromised Android devices used for activities including ad fraud, data theft and residential proxy traffic.
Kaspersky security researcher Dmitry Kalinin said the case showed attackers were extending malware attacks to new platforms, with legitimate software-update functions providing another route into connected automotive systems.















