Kaspersky says it has documented the first malware campaign built specifically for Android car head units — the touchscreen systems that handle music, navigation and, on some vehicles, parts of the car’s own controls. The findings were published on 21 August, and the awkward part for anyone driving with one of these screens in the dashboard is that neither of Kaspersky’s two write-ups names a single car brand or head unit model. The infected devices are described only as “multiple models” running firmware from a supplier called DoFun, so a reader currently has no reliable way to check whether the box in their dashboard is one of them.

How the Android head unit malware got in
The entry point was not a dodgy APK a driver sideloaded. It was the update system the head unit already trusts. DoFun firmware ships a legitimate system app called TWCore, which collects analytics and installs software updates pushed from the manufacturer’s side over an MQTT message broker. Kaspersky’s researchers found that TWCore’s update instructions carry a flag that allows it to install apps that were never on the device to begin with — and that attackers used exactly that channel to push a previously unknown dropper, JarService, straight onto the units.
From there it runs in three stages. JarService pulls down a loader that reports device details back to a command server; the loader then fetches a third component that can serve ads, commit ad fraud and download further modules. Kaspersky counted nine distinct commands available to the operators, and says the data flowing back included display resolution, device model, the connected Wi-Fi network identifier and the device’s MAC address. The payload actually being deployed at the time of the report was a reverse proxy module named zhima — meaning the real business here is renting out the car’s internet connection as a residential proxy, not stealing anything from the car itself.
Kaspersky attributes the campaign to the MoYu Group, an actor it links to the BadBox botnet already known for shipping compromised Android TV boxes. The connection was drawn partly from the operators’ own admin panel, which Securelist found sharing sign-in URL patterns and legal-document links with two residential proxy vendors, PXYEDGE and ProxyForU.
“This malware has become the very first malicious application specifically targeting car head units through an infection chain explicitly tailored for these vehicle systems,” said Dmitry Kalinin, security researcher at Kaspersky, in the company’s press release.
“Fixed” by the vendor is not the same as fixed in your car
Kaspersky notified DoFun, and says that according to DoFun the issue has been fixed. That sentence is doing a lot of work. A head unit is not a phone with a monthly security patch: factory-fitted units are updated at the pace of the carmaker’s service schedule, and aftermarket units bought online are frequently abandoned by their sellers within a year or two. A patch existing at the supplier and a patch reaching the screen in a specific car are two entirely different claims, and only the first one has been demonstrated here.
The wider point is one Android owners have run into before with cheap set-top boxes: when a device’s own update channel is the attack surface, none of the usual advice applies. The user did nothing wrong, installed nothing, and would see nothing — the malware runs with no interface at all.
What head unit owners can do now
- Install pending firmware updates from the head unit’s own settings or from the manufacturer’s site, since the fix DoFun reports can only reach you that way.
- Check whether the unit has a SIM slot in use. Kaspersky notes head units often carry their own SIM and permanent connectivity, which is precisely what makes them worth hijacking as proxies. If you never use the built-in data connection, there is no reason to leave it active.
- Watch for pop-up ads on the dashboard screen, which is the one symptom of this family a driver might actually notice — the same ad-fraud behaviour that shows up as invasive ads on phones.
- Be sceptical of no-name aftermarket units. A cheap Android head unit from an unknown seller carries the same update-channel risk as a cheap Android TV box, with no meaningful support commitment attached.
The gap that remains is the one Kaspersky’s report does not close: without a list of affected models, the practical advice stops at “update everything and hope your supplier shipped it.” For a device class that sits on a permanent internet connection inside a car, that is not a comfortable place to leave things.
Sources: Securelist, Kaspersky






