First malware designed for car head units expands botnet reach

Kaspersky found the first malware for Android car head units on DoFun infotainment systems, delivered via an update flaw and linked to the BadBox botnet.

Researchers at Kaspersky identified malware created for Android-based car head units on aftermarket DoFun infotainment systems. Attackers delivered the malicious apps by compromising the devices’ software update distribution channel.

The attackers exploited a flaw in the component that handles software updates to push Android packages that installed without user interaction. Kaspersky’s analysis found the delivered suite included droppers, loaders, an ad clicker and a reverse-proxy loader. The malware supports nine commands, including instructions to display ads, run ad-clicking routines and download additional modules. Researchers observed only commands that fetched a reverse-proxy module.

The reverse-proxy module lets an infected head unit relay network traffic and act as an exit point for other internet connections. That capability can be used to hide malicious traffic, support ad-fraud or route other traffic while obscuring the operator’s location.

Kaspersky attributed the operation to the MoYu Group, which has been linked to the BadBox botnet. BadBox has been active since at least 2023 and has been used to enlist compromised Android devices for fraud and related abuse. Security actors and law enforcement have worked to disrupt BadBox. Last year Google filed a lawsuit against operators of BadBox 2.0, saying the botnet had enrolled more than 10 million Android devices, mainly TV boxes.

DoFun told Kaspersky it patched the specific update-handling weakness after being notified. Kaspersky noted many aftermarket infotainment systems run custom Android builds and may not receive frequent security updates, which can extend the time devices remain vulnerable.

Kaspersky’s report states the discovery broadens the types of devices targeted by mobile-focused botnet operators to include vehicle infotainment systems and highlights risks in update-distribution channels for aftermarket automotive electronics.

Articles by this author