Breaking
Elche vs Barcelona: La Liga – prediction, team news, lineupsDefence Minister to explain ATM issues to Johor RegentMalaysia wins bid to host ICOPA 2030 in KuchingSword attack at Swedish school kills one, injures two, probes online linksElderly woman allegedly pressured into spending HK$100,000 on beauty productsAndroid car infotainment systems infected via DoFun appNamed Pipes Under Attack: Securing Windows Interprocess CommunicationTikTok to pay $400 million to settle US child privacy lawsuitMalaysia's semiconductor upstarts reach RM10 billion combined valuation in six monthsPelni Ambon starts aid deliveries for NTT earthquake victimsArsenal crush Coventry 3-0 to launch Premier League title defenceKemendag ships West Java coffee worth Rp2.64 billion to UKKuala Lumpur office vacancy hits 30% as older blocks lose ground to modern stockMichael Polansky is training an AI model on skin that's still alivePixel 11 Pro XL review: Snappier cameras can’t hide an iterative upgradeCNA explains why Trump is pushing to meet Kim Jong Un again.Hextar Healthcare 1H Loss Swells To RM12.5 Million On Poor Sale, High Operation CostsCloudflare launches Bot Preference Sync to unify AI bot rules in robots.txtCyber gang turns developer tools into trojan horses, Unit 42 findsSomalia faces collapse in child nutrition as aid cuts shutter facilitiesElche vs Barcelona: La Liga – prediction, team news, lineupsDefence Minister to explain ATM issues to Johor RegentMalaysia wins bid to host ICOPA 2030 in KuchingSword attack at Swedish school kills one, injures two, probes online linksElderly woman allegedly pressured into spending HK$100,000 on beauty productsAndroid car infotainment systems infected via DoFun appNamed Pipes Under Attack: Securing Windows Interprocess CommunicationTikTok to pay $400 million to settle US child privacy lawsuitMalaysia's semiconductor upstarts reach RM10 billion combined valuation in six monthsPelni Ambon starts aid deliveries for NTT earthquake victimsArsenal crush Coventry 3-0 to launch Premier League title defenceKemendag ships West Java coffee worth Rp2.64 billion to UKKuala Lumpur office vacancy hits 30% as older blocks lose ground to modern stockMichael Polansky is training an AI model on skin that's still alivePixel 11 Pro XL review: Snappier cameras can’t hide an iterative upgradeCNA explains why Trump is pushing to meet Kim Jong Un again.Hextar Healthcare 1H Loss Swells To RM12.5 Million On Poor Sale, High Operation CostsCloudflare launches Bot Preference Sync to unify AI bot rules in robots.txtCyber gang turns developer tools into trojan horses, Unit 42 findsSomalia faces collapse in child nutrition as aid cuts shutter facilities
Economy

Android car infotainment systems infected via DoFun app

Kaspersky researchers discovered malware that turns Android-based car head units into proxy-botnet nodes or ad-fraud machines.

Source: BleepingComputer · August 22, 2026 at 3:46 PM · AI-assisted report

Single-source
Android car infotainment systems infected via DoFun app
Image: bleepingcomputer.com

KUALA LUMPUR, 22 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Lead A supply‑chain attack has infected Android‑based car head units with malware that turns the devices into proxy botnet nodes or uses them for advertising fraud. The operation, attributed to the MoYu threat group, exploits a legitimate device‑update application distributed by DoFun, a Chinese automotive software provider. The incident raises concerns for automotive cybersecurity and the growing threat of compromised in‑vehicle infotainment systems.

Market Impact

Background and History of the Issue DoFun, owned by Shenzhen Driving Control Technology Co., Ltd., supplies generic Android head units that serve as the command centre for a vehicle’s infotainment, navigation and settings systems. In June, Kaspersky researchers discovered a rogue APK file being downloaded from DoFun’s legitimate system app, TWCore. The file, named JarService, has no user interface and is a piece of malware that decrypts and executes a second‑stage loader.

The loader establishes communication with a command‑and‑control (C2) server and downloads an encrypted payload that periodically reports device information such as model, display resolution, Wi‑Fi SSID and MAC address, and retrieves commands from the attackers. This is the first documented case of a malware infection chain specifically created for a car head unit.

Current Development Detail Kaspersky attributes the operation to the MoYu group, previously linked to the BadBox malware botnet. The malware does not interfere with driving or critical vehicle control systems, but is designed for advertising fraud and monetising the head units as residential proxy nodes. Researchers found that the operator primarily loaded a reverse‑proxy module named “zhima,” which turns the head unit into a proxy botnet node, and also made web requests for click‑fraud activity.

Kaspersky notified DoFun of its findings; the Chinese firm replied that it resolved the problem. BleepingComputer has contacted both companies with questions about the initial compromise vector, and will update the article once information is received.

Malaysia Market Impact The incident underscores the vulnerability of connected vehicles in Malaysia, where the automotive industry is rapidly adopting Android‑based infotainment systems. While the malware does not affect vehicle safety, it exposes Malaysian consumers to privacy risks and potential financial loss through click‑fraud. Local automotive manufacturers and suppliers that source head units from DoFun or similar providers may need to review their supply‑chain security practices.

The Malaysian Communications and Multimedia Commission (MCMC) may consider issuing guidance on securing in‑vehicle infotainment systems, and the Ministry of Transport could explore regulatory measures to ensure that automotive suppliers meet cybersecurity standards.

Sector/Company Specifics from the Source - DoFun: Chinese automotive software and hardware provider, owner of Shenzhen Driving Control Technology Co., Ltd. Supplies generic Android head units. - MoYu Group: Threat actor linked to BadBox malware botnet, responsible for the current operation. - JarService: Rogue APK file downloaded via TWCore, the legitimate DoFun system app. - zhima: Reverse‑proxy module used to create a proxy botnet node. - Kaspersky: Conducted the analysis and attribution.

- BleepingComputer: Reported the incident and is seeking further details from the involved parties.

Outlook Details not yet available on the extent of the compromise across the global fleet of DoFun head units. Kaspersky’s findings suggest that once attackers gain valid credentials, prevention measures drop sharply, highlighting the need for authentication and monitoring of firmware updates. The automotive sector should adopt a zero‑trust approach to supply‑chain security, ensuring that all software updates are signed and verified.

Regulatory bodies in Malaysia and elsewhere may introduce stricter cybersecurity requirements for automotive infotainment systems. Until a comprehensive assessment is completed, stakeholders should remain vigilant and consider implementing additional network segmentation and anomaly detection to mitigate potential exploitation of compromised head units.

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.