HackMyIP
← Back to News
2026-08-21 The Hacker News

DoFun Head Unit Malware Turns Android Cars Into BADBOX Proxy Bots

MalwareSupply ChainThreat Intel

Kaspersky researchers have uncovered a first-of-its-kind malware family targeting Android-based automotive head units built on DoFun firmware, exploiting the devices' built-in software update channel to build an ad fraud and residential proxy botnet. The campaign, attributed with high confidence to the MoYu Group—the same threat actor behind the BADBOX operation previously outed by HUMAN's Satori team—was first identified in June 2026 and delivers a multi-stage downloader through a legitimate system application called TWCore ("com.tw.core"), which communicates with an MQTT message broker hosted on the cardoor[.]cn subdomain. Operators weaponized the update pipeline to push malicious APK files to the "/push/apk/" path for silent installation, marking the first documented infection chain specifically engineered for in-vehicle infotainment systems.

The entry point is a dropper dubbed JarService, which deploys a loader that performs device reconnaissance and reports implant details to an attacker-controlled server via HTTP POST. Because Android-powered head units typically include SIM card slots for navigation and over-the-air updates, infected devices gain persistent network access—making them ideal nodes for residential proxy infrastructure and large-scale ad fraud. Network defenders and car owners concerned about unauthorized traffic can verify suspicious routing with the VPN/proxy detector or run a DNS leak test to confirm whether their network is being silently rerouted through a compromised device.

Google filed a lawsuit in July 2025 against 25 unnamed Chinese individuals and entities alleged to operate the BADBOX botnet, yet the MoYu Group has continued to evolve its tradecraft—now leveraging pre-installed system apps and legitimate update functionality rather than sideloaded APKs to evade detection. Kaspersky's Dmitry Kalinin noted that delivery methods have grown increasingly diverse, ranging from factory backdoors to compromised IPTV applications. Following responsible disclosure, DoFun has remediated the update mechanism abuse, but the campaign underscores a broader risk: as Android head units proliferate across both aftermarket and factory installations, they inherit the full Android threat surface, transforming connected vehicles into attractive footholds for botnet operators seeking persistent residential IP resources.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

IP Lookup →IP Blacklist Check →VPN & Proxy Detector →

Related Guides

Learn the background behind this story:

What is a DDoS attack? →What is a proxy server? →Is my IP blacklisted? →