logo

First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet

ID: c2e2b896-cbb8-5e54-bb32-74494dccaf58

STIX ID: report--c2e2b896-cbb8-5e54-bb32-74494dccaf58

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Mayura Kathir

...
...

Kaspersky researchers uncovered a June 2026 multi-stage Android malware campaign that hijacked the TWCore updater on DoFun automotive head units to silently install a headless dropper (JarService), a reflective loader, and a third-stage proxy/ad-fraud framework (zhima) that enrolled vehicles into a residential proxy botnet; attribution links the operation to the MoYu Group/BADBOX ecosystem and the report includes domains, IPs, and behavioral telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.