First Malware Built Specifically for Car Head Units Fuels Botnet
New malware targets car head units, fueling the BadBox botnet with millions of devices.
Summary
Kaspersky researchers have identified the first malware specifically designed for car head units, exploiting a vulnerability in the software update system of DoFun infotainment systems. This malware is linked to the BadBox botnet, which has already compromised millions of Android devices, and suggests an expansion of the threat actors' targeting methods beyond budget devices.
Full text
Researchers at Kaspersky have come across what appears to be the first malware specifically designed for car head units, and have found links to the notorious BadBox botnet. The malware was discovered on an Android-powered aftermarket infotainment system made by Chinese company DoFun, which is widely used in China and other APAC countries. Threat actors exploited a vulnerability in a system designed to handle software updates, enabling them to deliver malware to vehicle head units, Kaspersky explained. The vendor said it addressed the weakness after being notified. The attackers compromised the update distribution channel to deliver stealthy malicious Android applications that served as droppers, loaders, clickers, and reverse-proxy loaders. The malware supports nine commands, including ones that enable its operators to display ads, conduct ad fraud (via the clicker component), and download additional components. However, Kaspersky researchers have observed only commands to download a reverse proxy module, suggesting that the main goal is to ensnare devices in a proxy botnet.Advertisement. Scroll to continue reading. Further analysis led the security firm to strongly believe that the malware is the work of the MoYu Group, one of several entities previously linked to the development and operation of the BadBox botnet. BadBox has been around since at least 2023, enabling its operators to use hacked Android devices for fraud and other illegal schemes. Law enforcement has attempted to disrupt it, but the threat has grown exponentially. Google last year filed a lawsuit against the operators of BadBox 2.0, warning that the botnet had ensnared more than 10 million Android devices, mainly TV boxes. BadBox malware is often pre-installed on budget devices, but attacks targeting vehicle infotainment systems show that its operators are expanding their delivery methods and targets. Related: Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight Related: Rust Supply Chain Attack Linked to North Korean Hackers Related: AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Personal Information Exposed in Apollo Global Data BreachAnthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source FundBanking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the SpotlightContractors’ CMMC Confidence Rises as Ability to Prove It Falls BehindHackers Target Zimbra Servers in Active Exploitation CampaignOpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training PausesHackers Using AI to Target Siemens PLCs in Critical US SectorsCl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign Latest News Silent Patches Don’t Stop Attackers – They Blind DefendersTaiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro StaffCISA Warns of Exploited Oracle WebLogic VulnerabilityReliaQuest Confirms ShinyHunters Hack, but Says Impact Was LimitedHired for One Job, Judged on Another: The CISO’s Real ProblemUber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts91 Vulnerabilities Patched in Spring Application FrameworkVenezuelan Gets Record Federal Prison Term for ATM Jackpotting Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveDevi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.Forcepoint has named Proofpoint veteran Vincent Merlin as its new Chief Marketing Officer.Vensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer.More People On The MoveExpert Insights Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — BadBox