HackMyIP
← Back to News
2026-08-25 SecurityWeek

First Car Head Unit Malware Linked to BadBox Botnet Discovered

MalwareVulnerabilityThreat Intel

Security researchers at Kaspersky have identified what they believe is the first malware strain built specifically to target automotive head units, and it carries strong links to the notorious BadBox botnet. The malware was discovered on an Android-powered aftermarket infotainment system manufactured by Chinese vendor DoFun, a product widely deployed across China and other APAC markets. Attackers exploited a weakness in the device's software update mechanism, compromising the distribution channel to silently deliver malicious Android applications disguised as legitimate system components. The vendor addressed the flaw after being notified by Kaspersky.

Once installed, the malware functions as droppers, loaders, clickers, and reverse-proxy loaders, supporting nine distinct commands for its operators. These capabilities enable ad fraud through automated clicking and allow adversaries to display advertisements on infected units. However, Kaspersky's telemetry shows that only the reverse-proxy download command has been actively used in observed attacks, suggesting the primary objective is to enroll vehicle head units into a proxy botnet. Analysts tracking suspicious network behavior from connected devices can run traffic through a VPN and proxy detector to identify whether their hardware is being routed through unauthorized intermediaries.

Further investigation by Kaspersky linked the campaign to the MoYu Group, one of the threat actors previously tied to BadBox, which has been operational since at least 2023. BadBox traditionally pre-installs on low-cost Android devices—primarily TV boxes—and Google filed a lawsuit last year against its operators after the botnet expanded to more than 10 million infected devices in what has been dubbed BadBox 2.0. The pivot toward automotive head units signals that BadBox affiliates are diversifying both their delivery methods and target hardware, extending their reach beyond living rooms into vehicles. Connected car owners should audit their networks with a port scanner and run a privacy checkup to confirm no unauthorized services are communicating from their infotainment systems.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

IP Lookup →IP Blacklist Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a DDoS attack? →What is a proxy server? →Is my IP blacklisted? →