First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet
ID: c2e2b896-cbb8-5e54-bb32-74494dccaf58
STIX ID: report--c2e2b896-cbb8-5e54-bb32-74494dccaf58
Feed Name: GBHackers
Threat Score
Kaspersky researchers uncovered a June 2026 multi-stage Android malware campaign that hijacked the TWCore updater on DoFun automotive head units to silently install a headless dropper (JarService), a reflective loader, and a third-stage proxy/ad-fraud framework (zhima) that enrolled vehicles into a residential proxy botnet; attribution links the operation to the MoYu Group/BADBOX ecosystem and the report includes domains, IPs, and behavioral telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
