BadBox Malware Hijacks Android Car Head Units Through Firmware Updates — Security article on gikiewicz.com

TL;DR: Kaspersky has documented the first Android malware targeting automotive head units, delivered through the built-in firmware updater of DoFun head units. Discovered in June 2026, the malware serves ads and deploys the zhima proxy module linked to the BadBox botnet and the MoYu Group.

Kaspersky researchers have discovered what they describe as the first Android malware specifically designed to infect automotive head units. The threat, uncovered in June 2026, abuses the built-in firmware update mechanism of DoFun head units to install ad-fraud payloads and proxy botnet components. Security firms including BleepingComputer and SecurityAffairs have linked the operation to the wider BadBox botnet and the China-associated MoYu Group.

What Is the New Android Malware Infecting Car Head Units?

It is the first documented Android malware family that specifically targets automotive head units rather than phones or tablets. According to Kaspersky’s Securelist report, published in August 2026, the malware was discovered in June 2026 and spreads through the built-in updaters of the head unit firmware. Instead of relying on malicious app stores or phishing links, the operators compromised a legitimate software channel.

The head units themselves are aftermarket Android-based infotainment screens, sold as upgrades for older vehicles that lack modern connectivity. Because these devices run full Android, they inherit the platform’s entire attack surface. That is the core problem. Kaspersky notes the malware serves unwanted ads, collects device data, and can download additional modules in the background.

SecurityAffairs reports that the campaign effectively turns infected head units into nodes of the BADBOX network, a botnet previously associated with compromised Android TV boxes and other budget devices. CyberInsider emphasizes that this is the first time Android malware has spread through a car infotainment firmware update mechanism at all.

How Does the Malware Get Into Car Infotainment Systems?

The infection vector is the firmware update mechanism itself. TechNadu explains that the malware abuses DoFun firmware and the TWCore update mechanism, the component responsible for downloading and installing system updates on the head unit. By hijacking this trusted channel, attackers bypass the normal scrutiny applied to sideloaded apps.

SC Media confirms that the malware spreads through the built-in updaters of the head unit firmware, meaning users do nothing wrong to get infected. The update arrives looking legitimate. It installs cleanly. The victim never sees a prompt or warning.

This matters because firmware updaters typically run with elevated privileges on Android. Code delivered through that channel can persist across reboots, modify system partitions, and resist removal by conventional means. PCMag reports that the affected vendor, DoFun, is based in Hong Kong and supplies software for Android-based car head units, giving the attackers a large installed base of potential targets.

The attack also highlights a broader gap. Connected-vehicle security discussions usually focus on ECUs and CAN buses, but the infotainment unit is an internet-connected Android computer sitting on the dashboard.

Who Is DoFun and Why Does Its Software Matter?

DoFun is a Hong Kong-based vendor that supplies software for Android-based car head units, according to PCMag and Kaspersky. Its firmware and update tooling ship inside aftermarket infotainment screens sold across multiple markets. This matters because any compromise of DoFun’s update pipeline potentially reaches every device that trusts it.

Aftermarket head units are a huge, largely invisible market. Owners of older cars buy them to add navigation, streaming, and touchscreen controls that their vehicles never had. These devices rarely receive long-term security support, and their supply chains are opaque.

News4Hackers notes that the campaign exploits exactly this kind of trusted channel, highlighting security gaps in connected car accessories. When the updater is the attack vector, standard advice like “avoid sideloading apps” becomes useless. The user did everything right.

For DoFun customers, the practical implication is stark. The very mechanism designed to keep the head unit current became the delivery system for malware. Kaspersky has not stated how the attackers initially compromised the update infrastructure, but the result is the same: trusted software turned hostile.

What Does the Malware Actually Do Once Installed?

Once installed, the malware pursues two goals: ad fraud and botnet recruitment. Kaspersky’s Securelist analysis states the malware is designed to serve ads and build a proxy botnet, displaying unwanted advertisements and collecting device data from the infected head unit.

Pravda’s English coverage adds that the malware can download additional modules via background operations, meaning the initial payload is not the full capability. The operators can push new functionality to infected units on demand. That is what makes this dangerous.

For the victim, the symptoms are subtle. Ads appear where they should not. The unit may slow down. Data such as device identifiers gets harvested silently. Because the payload runs at firmware level, uninstalling an app or factory-resetting the unit may not remove it.

For the operators, each infected head unit becomes a monetizable node. Ad fraud generates revenue directly, while the proxy module adds the device to a resale network. SecurityAffairs reports that the proxy software effectively enrolls the head unit into the BADBOX network, the same infrastructure previously built from infected smart TV boxes.

What Is the zhima Proxy Module and How Does It Work?

The zhima module is the component that converts an infected head unit into a proxy exit node. TechNadu reports that the malware deploys the zhima proxy module through the TWCore update mechanism, and that this module is linked to the MoYu Group and the BadBox botnet.

Proxy modules work by opening an outbound connection from the infected device to attacker-controlled infrastructure. Once connected, third parties can route their traffic through the victim’s IP address. The car owner pays for the connectivity. Someone else uses it.

Infobae’s coverage connects the campaign to the MoYu Group, the actor associated with the BadBox network of infected devices. BadBox has previously been documented monetizing large fleets of compromised Android hardware by selling proxy access, and this campaign extends that model to vehicles.

Kaspersky’s discovery marks the first time this proxy architecture has been observed on automotive head units. Every infected screen in every car becomes a small anonymous relay. The owner has no idea their dashboard is laundering someone else’s traffic.

Is This Campaign Connected to the BadBox Botnet?

Yes, researchers have linked this campaign to the BadBox botnet, a large network of infected Android devices that has been active for years. According to Kaspersky’s analysis, the malware deployed on DoFun head units includes the zhima proxy module, a component previously associated with BadBox operations run by the MoYu Group. This marks the first documented case of BadBox-linked malware reaching automotive hardware through a firmware update channel.

BadBox originally gained attention by infecting cheap Android devices — such as streaming boxes and digital picture frames — before they even reached consumers. Now the same infrastructure has found its way into cars. The head units essentially become proxy exit nodes, letting criminal customers route their traffic through unsuspecting drivers’ vehicles. That is a serious escalation.

The connection matters for attribution. Security Affairs and Cyber Insider both report that the campaign abuses car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX network. In other words, your dashboard stereo becomes someone else’s anonymous relay. And the driver never notices a thing.

Who Is Behind the Attack: What Is the MoYu Group?

The MoYu Group is a China-linked cybercriminal operation that Kaspersky and other vendors have tied to the BadBox botnet and its associated fraud ecosystem. According to Infobae’s coverage of the discovery, the campaign targeting vehicle screens is directly linked to MoYu Group, which operates the broader network of infected devices used for ad fraud and proxy monetization. The group’s business model is simple: infect cheap Android hardware at scale, then rent out that capacity.

What makes MoYu distinctive is its supply-chain approach. Rather than phishing individual users, the group embeds its malicious modules into firmware or legitimate-looking software distributed through trusted update channels. In this campaign, the malware arrived through DoFun’s built-in updater — software that head unit owners had every reason to trust. TechNadu’s reporting confirms the zhima proxy module deployed via the TWCore update mechanism carries the MoYu signature.

The group monetizes infected devices in two main ways: generating fraudulent ad impressions and selling proxy access to the network. A car head unit is an attractive addition because it stays powered on for long periods and connects to mobile networks. That means stable, always-available bandwidth for proxy customers.

Why Are Aftermarket Head Units Such an Easy Target?

Aftermarket Android head units are easy targets because they combine outdated Android versions, minimal security hardening, and obscure update channels that owners cannot verify. Kaspersky’s Securelist report describes these devices as running full Android systems with background operations that can silently download additional modules — exactly the capability this malware exploits. The devices ship with broad permissions and no app store oversight.

Consider the typical supply chain. A vendor in one country assembles the hardware, another licenses the Android software, and firmware updates flow through mechanisms like TWCore that nobody audits. PCMag notes that DoFun, a Hong Kong-based vendor supplying software for Android head units, was the distribution vector here. When the updater itself is compromised, standard advice like “only install official updates” collapses.

The problems compound from there:

  • Head units rarely receive Android security patches after purchase
  • Owners have no way to inspect or verify firmware images before installation
  • The devices run continuously with persistent network connections
  • No antivirus or monitoring tools exist for this hardware category
  • Manufacturers disappear quickly, leaving orphaned products without support
  • Debug interfaces and ADB access are often left enabled in production builds
  • Users grant the infotainment system extensive permissions by default
  • There is no kill switch — no simple way to wipe and reflash safely

Cheap manufacturing makes it worse. Budget units cut corners on secure boot and code signing, so a malicious firmware component can load without any integrity check failing. The economics of the aftermarket segment simply do not reward security investment.

How Was the Threat Discovered and Reported?

Kaspersky discovered the threat in June 2026, according to SC Media, when researchers identified malware spreading through the built-in updaters of Android head unit firmware. The company’s Securelist unit published a detailed technical writeup titled “First Android malware targeting automotive head units,” documenting how the malicious code rides the legitimate DoFun software update path. The disclosure came roughly two months before broader media coverage in August 2026.

The reporting timeline tells its own story. After Kaspersky’s initial findings, outlets including BleepingComputer, The Hacker News, Security Affairs, and Cyber Insider picked up the research and connected it to earlier BadBox reporting. The Hacker News framed it as the first known Android car malware spreading through built-in updaters for ad fraud and proxy botnet activity. That framing matters — this is a documented first for the automotive platform.

Kaspersky’s researchers noted that the malware collects device data and displays unwanted ads while maintaining the proxy connection in the background, as reported by Pravda’s English edition. The discovery highlights how little visibility anyone has into infotainment firmware until a major vendor investigates. Nobody was looking for car malware before this.

How Can Drivers Protect Their Android Head Units?

Drivers can reduce risk by avoiding untrusted firmware updates, disconnecting head units from unnecessary network connections, and preferring mainstream brands with documented security practices. Since the malware spreads through the DoFun updater and the TWCore mechanism, the most direct protection is refusing updates from sources you cannot independently verify. If your unit came from an unknown AliExpress-style vendor, treat every update prompt with suspicion.

Practical steps include:

  • Research the exact head unit model and its software vendor before buying
  • Check whether the vendor has any documented security policy or update signing
  • Disable automatic firmware updates if the option exists
  • Avoid connecting the head unit to Wi-Fi networks it does not need
  • Use a separate SIM or hotspot rather than sharing your phone’s connection permanently
  • Monitor data usage — unexpected consumption can signal proxy activity
  • Watch for unfamiliar ads appearing outside any app you opened
  • Prefer head units running recent Android versions with verified boot
  • Contact the vendor if your device shows DoFun or TWCore components
  • Replace deeply compromised units rather than trusting a “clean” reflash from forums

No dedicated removal tool exists for this malware yet. Because it lives in the firmware layer, a factory reset of the Android interface will not remove it. Owners of affected units may ultimately need a clean firmware image from a trustworthy source — something many budget vendors simply cannot provide.

Frequently Asked Questions

Can this malware affect any car with an Android head unit?

No — the documented campaign specifically targets head units running DoFun software, which Kaspersky identified as a Hong Kong vendor supplying Android-based infotainment systems. However, the attack technique of hijacking built-in firmware updaters could theoretically work against any vendor with a similar unverified update mechanism. The risk is concentrated in aftermarket units rather than factory-installed systems from major automakers.

Does the malware steal personal data from drivers?

The malware primarily collects device data and displays unwanted ads rather than harvesting personal files, according to Kaspersky’s findings reported by Pravda and Infobae. Its main criminal purpose is operating the zhima proxy module, which routes third-party traffic through the infected head unit. That proxy function does not expose your documents or photos, but it does consume your data allowance and could implicate your connection in other parties’ activity.

Has this kind of car malware been seen before?

No — Kaspersky describes this as the first Android malware specifically targeting automotive head units, discovered in June 2026. Earlier BadBox campaigns infected TV boxes, streaming sticks, and other cheap Android devices, but never vehicle infotainment hardware. The Hacker News notes this is also the first documented case of car malware spreading through built-in updaters, making it a genuine first for the platform.

Should owners remove DoFun software from their head units?

Simply uninstalling DoFun software is not enough, because the malicious components were delivered through the firmware update mechanism itself and persist at a deeper level. Kaspersky’s research shows the malware uses background operations to download additional modules, meaning a surface-level cleanup leaves the infection intact. Owners should check whether their unit uses the TWCore updater, stop applying further updates, and seek a verified clean firmware image or replace the unit.

Summary

The BadBox campaign against Android car head units marks a genuine first: automotive infotainment compromised through its own trusted firmware update channel. Kaspersky’s June 2026 discovery showed that DoFun head units, updated through the TWCore mechanism, were silently turned into proxy nodes and ad-fraud machines linked to the MoYu Group. The devices stay online, powered, and invisible to their owners — ideal properties for a botnet.

Key takeaways:

  • Kaspersky documented the first Android malware targeting automotive head units, delivered via the DoFun updater and TWCore update mechanism
  • The zhima proxy module links the campaign to BadBox and the MoYu Group, the same criminal ecosystem behind infected TV boxes and streaming devices
  • The malware monetizes infected cars through ad fraud and proxy traffic, collecting device data while hiding in background operations
  • Aftermarket head units are structurally vulnerable: outdated Android, no update verification, and no security tooling exist for this hardware class
  • Drivers should disable automatic updates on untrusted units, monitor data usage, and avoid budget infotainment vendors without documented security practices

If you own an aftermarket Android head unit, check what software vendor it uses before accepting the next update. Read the full Kaspersky report on Securelist, and share this article with anyone driving with a cheap Android dashboard installed.