Android car infotainment systems infected via DoFun app
Kaspersky researchers discovered malware that turns Android-based car head units into proxy-botnet nodes or ad-fraud machines.
Source: BleepingComputer · August 22, 2026 at 3:46 PM · AI-assisted report
Single-source
KUALA LUMPUR, 22 AUGUST 2026 —
Listen to this article
DomainFork Audio · read aloud
Lead A supply‑chain attack has infected Android‑based car head units with malware that turns the devices into proxy botnet nodes or uses them for advertising fraud. The operation, attributed to the MoYu threat group, exploits a legitimate device‑update application distributed by DoFun, a Chinese automotive software provider. The incident raises concerns for automotive cybersecurity and the growing threat of compromised in‑vehicle infotainment systems.
Market Impact
Background and History of the Issue DoFun, owned by Shenzhen Driving Control Technology Co., Ltd., supplies generic Android head units that serve as the command centre for a vehicle’s infotainment, navigation and settings systems. In June, Kaspersky researchers discovered a rogue APK file being downloaded from DoFun’s legitimate system app, TWCore. The file, named JarService, has no user interface and is a piece of malware that decrypts and executes a second‑stage loader.
The loader establishes communication with a command‑and‑control (C2) server and downloads an encrypted payload that periodically reports device information such as model, display resolution, Wi‑Fi SSID and MAC address, and retrieves commands from the attackers. This is the first documented case of a malware infection chain specifically created for a car head unit.
Current Development Detail Kaspersky attributes the operation to the MoYu group, previously linked to the BadBox malware botnet. The malware does not interfere with driving or critical vehicle control systems, but is designed for advertising fraud and monetising the head units as residential proxy nodes. Researchers found that the operator primarily loaded a reverse‑proxy module named “zhima,” which turns the head unit into a proxy botnet node, and also made web requests for click‑fraud activity.
Kaspersky notified DoFun of its findings; the Chinese firm replied that it resolved the problem. BleepingComputer has contacted both companies with questions about the initial compromise vector, and will update the article once information is received.
Malaysia Market Impact The incident underscores the vulnerability of connected vehicles in Malaysia, where the automotive industry is rapidly adopting Android‑based infotainment systems. While the malware does not affect vehicle safety, it exposes Malaysian consumers to privacy risks and potential financial loss through click‑fraud. Local automotive manufacturers and suppliers that source head units from DoFun or similar providers may need to review their supply‑chain security practices.
The Malaysian Communications and Multimedia Commission (MCMC) may consider issuing guidance on securing in‑vehicle infotainment systems, and the Ministry of Transport could explore regulatory measures to ensure that automotive suppliers meet cybersecurity standards.
Sector/Company Specifics from the Source - DoFun: Chinese automotive software and hardware provider, owner of Shenzhen Driving Control Technology Co., Ltd. Supplies generic Android head units. - MoYu Group: Threat actor linked to BadBox malware botnet, responsible for the current operation. - JarService: Rogue APK file downloaded via TWCore, the legitimate DoFun system app. - zhima: Reverse‑proxy module used to create a proxy botnet node. - Kaspersky: Conducted the analysis and attribution.
- BleepingComputer: Reported the incident and is seeking further details from the involved parties.
Outlook Details not yet available on the extent of the compromise across the global fleet of DoFun head units. Kaspersky’s findings suggest that once attackers gain valid credentials, prevention measures drop sharply, highlighting the need for authentication and monitoring of firmware updates. The automotive sector should adopt a zero‑trust approach to supply‑chain security, ensuring that all software updates are signed and verified.
Regulatory bodies in Malaysia and elsewhere may introduce stricter cybersecurity requirements for automotive infotainment systems. Until a comprehensive assessment is completed, stakeholders should remain vigilant and consider implementing additional network segmentation and anomaly detection to mitigate potential exploitation of compromised head units.