Android Car Head Units Targeted in Proxy Botnet and Ad-Fraud Campaign

A supply-chain compromise affecting Android-based automotive head units has been used to install malware that turns vehicles’ internet connections into proxy infrastructure and supports online adverti...

A supply-chain compromise affecting Android-based automotive head units has been used to install malware that turns vehicles’ internet connections into proxy infrastructure and supports online advertising fraud, according to researchers at Kaspersky.

The campaign has been attributed to MoYu, a threat group previously linked to the BadBox Android botnet. Kaspersky said the activity represents the first publicly documented infection chain developed specifically for automotive head units.

Malware delivered through update software

The operation targeted products from DoFun, a Chinese provider of automotive software, cloud services and hardware. Its generic Android head units commonly support infotainment, navigation and vehicle-setting functions.

In June, researchers observed an unfamiliar APK being delivered through TWCore, a legitimate DoFun system application responsible for device updates. The application reportedly received instructions through an MQTT server hosted on the cardoor[.]cn domain.

The malicious package, identified as JarService, has no visible user interface. Once started, it decrypts and runs a loader, contacts an attacker-controlled command-and-control server, and retrieves an additional encrypted component.

Proxy activity and click fraud

The final payload collects device details—including the head-unit model, screen resolution, Wi-Fi network name and MAC address—and periodically communicates with the operators. Its capabilities include making HTTP requests, opening webpages in a WebView, executing JavaScript, downloading further code, launching browser links and testing host availability.

Kaspersky said operators mainly deployed a reverse-proxy module called “zhima.” This component allows infected head units to act as residential proxy nodes, potentially enabling third parties to route traffic through the devices. Researchers also observed web requests consistent with advertising click fraud.

Although the malware has broad access to the Android environment, Kaspersky found no evidence that it interferes with driving functions or critical vehicle-control systems. The apparent objective is to monetize connected head units rather than disrupt vehicle operation.

Kaspersky notified DoFun, which said it had addressed the reported issue. The precise initial compromise method has not been disclosed. Owners and fleet operators using affected aftermarket or embedded Android head units should apply vendor updates, review unexpected system-app activity and limit devices’ network access where practical.