Hackers Turn Android Car Head Units Into Proxy Botnet
Kaspersky researchers have uncovered what appears to be the first documented malware campaign designed specifically to compromise Android-based car head units, targeting devices manufactured by Chinese automotive software provider DoFun. Head units—the in-vehicle computers that manage navigation, media, and Bluetooth connectivity—are being covertly recruited into a proxy botnet without requiring any action from drivers. The attackers exploited TWCore, a legitimate system application pre-installed on DoFun devices to handle analytics and software updates, abusing its ability to silently download and install new Android packages.
The malicious payload, dubbed JarService, was pushed directly to affected head units through TWCore's update mechanism, meaning victims never had to click a link, visit a malicious website, or knowingly install anything. JarService runs without a visible user interface and functions primarily as a downloader for additional malicious modules, making the infection extremely difficult for drivers to detect. Beyond generating fraudulent ad clicks, the malware's key capability is transforming each compromised head unit into a reverse proxy—routing third-party internet traffic through the vehicle's connection and effectively laundering cybercriminal activity behind a car owner's IP address. Users can verify whether their network is being suspiciously routed by running a VPN/proxy detector.
Kaspersky attributed the campaign with high confidence to MoYu Group, a threat actor linked to the BadBox malware operation, which has historically compromised Android smartphones, tablets, streaming devices, and TVs—often before they ever reach consumers. The campaign reflects how BadBox-linked actors continue to operate despite repeated law enforcement actions, including a December 2024 disruption by German authorities that severed command-and-control communications for the original botnet. The shift to automotive head units marks a worrying expansion into connected-vehicle infrastructure, where infections can persist unnoticed for years. Vehicle owners concerned about device integrity can perform a broader privacy checkup to assess their connected-device exposure.
Researchers confirmed that DoFun was notified of the distribution scheme and has since patched the underlying security issues in TWCore. However, any head units that received the malicious JarService payload before the fix remain compromised and continue functioning as proxy nodes for the botnet. Security professionals warn that the automotive sector must adopt stricter supply-chain vetting, similar to the measures used for smartphones and IoT devices, before connected cars become a more attractive target for similar proxy-ware and ad-fraud operations.