Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet
- Hackers exploited trusted software updates to deliver malware directly into car head units
- Kaspersky says this is the first campaign tailored specifically for vehicle head units
- The malware can run silently without showing drivers any visible interface
Car head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.
A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.
According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.
Latest Videos FromTechRadar
Compromised update channels deliver malware straight into vehicles
Researchers believe the activity can likely be traced back to the MoYu Group, a threat actor closely tied to the well-known BadBox botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by DoFun.
The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.
Attackers hijacked this trusted update channel using a specialized dropper called JarService to deliver previously unknown malware directly onto a range of affected devices.
Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.
The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device’s MAC address.
Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.
The research team claims that the botnet’s administration panel shares embedded URLs with residential proxy service websites PXYEDGE and ProxyForU.
BadBox itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.
Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.
According to statements from DoFun, the underlying issue has since been resolved across most affected devices currently deployed in the field.
Head units present a growing and largely unprotected attack surface
Car head units can arrive factory-installed directly from the manufacturer or get added later to older vehicles as aftermarket upgrades.
Manufacturers frequently rely heavily on the Android operating system because it simplifies interface customization and essential system integration work considerably.
This widespread industry reliance means most standard Android applications, along with most existing Android malware, can potentially run on these devices.
Head units rarely store sensitive personal data directly on board, which on the surface might suggest only limited appeal to attackers.
However, they typically include active SIM card slots and maintain constant internet connectivity for navigation services and routine software updates.
That particular combination of persistent connectivity and comparatively weak security oversight makes these systems a genuinely attractive prospect for attackers going forward.
The overall scale of this particular campaign remains genuinely unclear, and whether other head unit manufacturers face similar exposure is not yet known.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Hackers exploited trusted software updates to deliver malware directly into car head units Kaspersky says this is the first campaign tailored specifically for vehicle head units The malware can run silently without showing drivers any visible interface Car head units are now being drawn into a growing wave of Android…
Recent Posts
- Anthropic CEO Dario Amodei says people think governments are using AI ‘to screw them over’, and that’s why the tech is having a ‘a crisis of trust’ — and he’s exactly right
- Amazon knocks $150 off Pixel 11 phones, with up to $200 in gift cards
- Samsung leak reveals Galaxy Aero smartwatch-lite — and it could right the wrongs of Samsung’s disappointing Apple Watch SE rival
- Devolver Digital squares up to Rockstar with a mascot platformer out the same day as GTA 6
- Being a mom is hard — the heat is making it harder
Archives
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023