logo

Hackers infecting Android car systems to build proxy botnet

ID: 2510a48e-12ab-5e60-9df9-11a262a232ea

STIX ID: report--2510a48e-12ab-5e60-9df9-11a262a232ea

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

...
...

Kaspersky found a new malware campaign targeting DoFun Android head units that abuses a system updater (TWCore) to silently install a downloader app (JarService), turning infected car infotainment systems into ad-clicking bots and reverse proxies as part of a BadBox/MoYu Group botnet; the vendor was notified and fixes were reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.