logo

Hackers infect Android car head units with proxy botnet malware

ID: 52bf185f-e196-5c68-a6ab-4de7395c683a

STIX ID: report--52bf185f-e196-5c68-a6ab-4de7395c683a

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-08-22

Date Updated: 2026-08-22

Author: Bill Toulas

...
...

**Executive summary:** Kaspersky researchers uncovered a supply-chain compromise of DoFun Android head-unit software that delivered a multi-stage malware named JarService attributed to the MoYu group; the final payload registers device details, supports multiple remote commands, and primarily loads a reverse-proxy module (zhima) to enlist infected head units into a proxy botnet and carry out click-fraud, while not affecting vehicle control systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.