The automotive industry has long feared the day when the connected car becomes a vector for large-scale cyberattacks. That day has arrived. Security researchers at Kaspersky have uncovered the first documented malware campaign specifically engineered to hijack Androidaaa-based car head units, turning them into nodes for a sprawling proxy botnet and ad fraud operation. The campaign, which Kaspersky attributes with high confidence to the MoYu Group—the threat actors behind the notorious BADBOX malware ecosystem—exploits a legitimate firmware update mechanism in DoFun Android head units to silently install a malicious application called JarService. This discovery marks a significant escalation in the cyber threat landscape, demonstrating that vehicle infotainment systems and aftermarket head units now face the same supply-chain and update-channel risks as smartphones, smart TVs, and IoT devices.
How BadBox Malware Infects Car Head Units via Legitimate Update Channels
Unlike typical Android malware that relies on user installation from untrusted sources, BadBox-linked malware achieves infection through a stealthier, more insidious route. Kaspersky researcher Dmitry Kalinin first spotted the anomaly in June 2026 while monitoring Android threats. His team noticed an unusual application named JarService that installed like a normal app but had no user interface and made no effort to impersonate legitimate software. This immediately suggested that users were not installing it themselves; something else was pushing it onto the devices.
Further investigation traced the infection back to TWCore, a legitimate system application pre-installed on DoFun Android automotive head units. DoFun head units are widely used for multimedia, navigation, connectivity, and limited vehicle functionality, and they are either installed by automakers or sold as aftermarket upgrades. TWCore is designed for analytics collection and software updates, and it communicates with a remote MQTT server hosted at the domain cardoor[.]cn to receive update instructions. Crucially, one of TWCore’s settings—installNotExists—allows the updater to install applications that are not already present on the device. This feature, intended for legitimate firmware updates, is exactly what the attackers exploited.
Kaspersky telemetry showed JarService repeatedly appearing in TWCore’s APK download directory and being installed by the com.tw.core package. After being notified, DoFun reported fixing the security issues involved, but the infection chain had already proven its effectiveness.
What is JarService? The Multi-Stage Infection Mechanism
Once installed, JarService begins a multi-stage infection chain. It first acts as an intermediate loader, contacting an attacker-controlled command-and-control (C2) server to retrieve a secondary payload. This component then starts collecting information about the head unit, including its model, screen resolution, connected Wi-Fi network, and MAC address. It provides the attackers with a detailed fingerprint of every infected device.
The malicious framework can receive commands to open web pages, execute JavaScript, make arbitrary HTTP requests, manipulate clipboard data, and download additional code. While the framework supports a range of functions, Kaspersky observed the attackers primarily using it to install a module called zhima.
Zhima: Turning Head Units into Reverse Proxies for a Botnet
Zhima is the core component that transforms infected car head units into reverse proxies. This allows the attackers to route other internet traffic through the victim’s connection, effectively creating a residential proxy botnet. Residential proxies are highly valuable to cybercriminals because they make malicious traffic appear to originate from legitimate home or vehicle IP addresses, bypassing many security filters.
Kaspersky’s findings were independently corroborated by researchers from Nokia’s Deepfield Emergency Response Team, who identified the same malware family on TV set-top boxes. This cross-platform presence suggests the MoYu Group is operating a broad, multi-device botnet with a unified proxy and ad fraud infrastructure. The malware also supports automated advertising activity and click fraud, generating revenue by simulating human interaction with ads.
The Attribution to MoYu Group and the BADBOX Ecosystem
Kaspersky attributes this campaign with high confidence to MoYu Group, an actor previously associated with the BADBOX malware ecosystem. BADBOX, earlier detailed in reports about over one million infected devices, has evolved beyond smartphones and set-top boxes to include Android head units. The attribution is based on several factors: naming artifacts inside the malware code, significant similarities with malicious software found on set-top boxes, and substantial overlap in network infrastructure, including shared C2 servers and domain registration patterns.
During the investigation, researchers connected one zhima server to the domain admin.uipoxy[.]com, where they found a proxy administration panel. Registration pages on that panel referenced privacy and usage documents belonging to a commercial residential proxy provider, further suggesting that the botnet’s primary purpose is selling proxy services to third parties, likely for other criminal activities.
What Does This Mean for Vehicle Cybersecurity?
The discovery that Android-based vehicle head units can be compromised through their own update mechanism has profound implications for automotive cybersecurity. These head units often have persistent internet connectivity, run full Android operating systems, and—critically—receive software updates over the air. In many cases, they are installed by automakers or sold by aftermarket vendors with minimal security oversight. The attack chain bypasses traditional endpoint security because the malicious code is delivered through a trusted system process.
Vehicle owners and installers must now treat head units with the same security caution as any other connected device. Kaspersky recommends applying all vendor security updates promptly, avoiding unsupported or custom firmware builds, restricting unnecessary internet connectivity where practical, and monitoring for unexpected applications or anomalous network activity on Android head units. For fleet operators, the risk is multiplied: a single compromised head unit in a delivery truck or taxi could expose the entire corporate network through the vehicle’s cellular connection.
Infection Chain Visualized: From TWCore to Proxy Botnet
Kaspersky provided a detailed diagram of the infection chain, which can be summarized as follows:
- The attacker sends an MQTT command to the DoFun head unit’s TWCcore service via the cardoor[.]cn server.
- TWCore, using its installNotExists capability, downloads and installs JarService from a malicious APK.
- JarService contacts a C2 server and fetches an intermediate payload.
- The payload collects device information and installs the zhima reverse proxy module.
- Zhima opens connections that allow the attacker to route traffic through the head unit, enabling proxy services and ad fraud.
This chain is notable for its use of legitimate, built-in functionality—MQTT communication and system updaters—which makes detection by traditional antivirus tools difficult.
What is BADBOX Malware and How Does It Relate to This Campaign?
BADBOX is a large-scale malware ecosystem previously linked to MoYu Group, primarily targeting Android devices such as smartphones, tablets, and set-top boxes. It typically gains access through the supply chain, where compromised firmware or pre-installed malicious apps are distributed to unsuspecting users. The BADBOX botnet has been responsible for generating fraudulent ad clicks, launching proxy services, and even mounting distributed denial-of-service attacks. The car head unit campaign is a direct extension of this ecosystem, now exploiting the automotive aftermarket. The use of identical infrastructure and code patterns confirms that the same threat actors are diversifying into new device categories.
Practical Consequences for Drivers and Fleet Operators
For individual drivers, an infected head unit can cause more than just privacy intrusion. The proxy botnet consumes bandwidth and data, potentially leading to higher mobile data bills if the head unit uses a cellular connection. It can also cause slower performance and battery drain. More importantly, the head unit’s connection to the vehicle’s internal network—often through CAN bus or automotive Ethernet—could theoretically be used as a stepping stone to attack other vehicle systems, though Kaspersky noted no evidence of such escalation in this campaign.
Fleet operators face even greater risks. A compromised head unit in a logistics vehicle could expose the fleet management system, GPS data, and driver communications. The proxy botnet could also be used to exfiltrate data stored on the head unit, such as navigation history or paired smartphone contacts. Given that many modern fleet vehicles rely on Android-based infotainment systems for route optimization and driver safety, the security implications are severe.
How to Protect Your Android Car Head Unit from BadBox Malware
The first line of defense is ensuring that the head unit’s firmware is up to date. DoFun has already released a fix for the TWCore vulnerability, but users must install it. If an aftermarket head unit is running an older version of Android—especially versions below Android 9—it may lack security patches for known vulnerabilities. Kaspersky also advises:
- Disable automatic installation of unknown apps, even from trusted sources.
- Monitor network traffic from the head unit for unusual outbound connections, especially to unknown IP addresses or domains.
- Avoid using head units with custom ROMs or firmware from unverified sources.
- If an inexplicable application like JarService appears, factory reset the device and do not restore from backups taken during the infection period.
For fleet managers, segmentation of the vehicle’s network and strict access controls for aftermarket devices are strongly recommended. Treating head units as untrusted endpoints—just like any other IoT device—is a prudent strategy.
Broader Industry Implications: The Rise of Automotive Malware
This campaign represents a tipping point. While proof-of-concept attacks on connected cars have existed for years, the BadBox head unit infection is the first real-world, financially motivated malware campaign targeting automotive systems at scale. It demonstrates that threat actors are actively exploring vehicle attack surfaces beyond remote keyless entry hacks or CAN bus vulnerabilities. The use of proxy botnets—a staple of desktop and mobile malware—is now firmly established in the automotive context.
The automotive industry, particularly aftermarket vendors, must re-evaluate their software update security. Relying on unauthenticated MQTT commands or allowing arbitrary application installation through system updaters is no longer acceptable. Manufacturers should implement cryptographic verification for all updates, enforce minimum platform security requirements, and provide users with transparent logs of system modifications.
Regulators are also taking notice. The discovery may accelerate discussions around mandatory cybersecurity standards for aftermarket head units, similar to those already emerging for vehicle-to-everything (V2X) communications and over-the-air update systems. In the European Union, the UN Regulation No. 155 mandates cybersecurity management systems for vehicle types, but it currently focuses on original equipment manufacturers, leaving aftermarket components largely unregulated.
Looking at the Broader BADBOX Ecosystem
The BadBox malware ecosystem has been active for years, with previous reports from Kaspersky and others documenting infections across millions of devices. The shift to car head units follows a logical trajectory: as threat actors find it harder to infect smartphones—which are becoming better protected with Google Play Protect and monthly patches—they are turning to less secure device categories. Set-top boxes, smart TVs, and now head units offer a growing pool of always-on, internet-connected devices with weak update mechanisms and little security oversight.
MoYu Group’s infrastructure, including the cardoor[.]cn domain and the proxy administration panel on admin.uipoxy[.]com, provides a glimpse into the commercial side of the operation. By selling proxy access to other criminals, the group can monetize compromised devices without necessarily needing to conduct attacks themselves. This business model makes the botnet resilient and difficult to dismantle, as disrupting one domain or server only shifts traffic to another.
For security researchers, the discovery underscores the importance of monitoring all Android-based devices—not just those in consumers’ pockets. Head units, in particular, represent a blind spot for most enterprise security teams. As vehicles become more connected, this blind spot will grow unless organizations actively seek visibility into the devices on their network periphery.
Follow us on X/Twitter and LinkedIn for more exclusive content.