Android car systems abused by hackers to launch new malware that pulls devices into a hidden proxy network
- Kaspersky found Android malware abusing DoFun car head units via TWCore updates
- Multi‑stage attack installs loaders and reverse proxy, aiming to build a botnet of connected cars
- Campaign attributed to MoYu Group; DoFun patched vulnerabilities after disclosure
We’ve seen botnets comprising cameras and DVRs, we’ve even seen botnets comprising smart fridges and digital frames, but we’ve never seen botnets comprising automobile infotainment systems. First time for everything.
Earlier this week, security researchers Kaspersky warned about finding a brand new Android malware targeting the car’s head unit. The victim seems to be a Chinese manufacturer called DoFun. Head units from this manufacturer, built on Android, are running an app for analytics and software updates called TWCore.
According to Kaspersky, the attackers abused TWCore’s update mechanisms, instructing it to download a malicious APK. This malware is then placed in the app’s cache directory and installed by the legitimate com.tw.core package.
Latest Videos FromTechRadar
No active campaigns
The researchers said this was a multi-stage attack. In the first stage, a tiny dropper with no user interface gets deployed. It decrypts embedded data, and extracts the information it needs for stage two. In the next stage, the loader contacts the attackers’ server and gets instructions about stage 3, which can be different things, from deploying additional malware, to running the “zhima” reverse proxy.
Despite its multifunctional nature, Kaspersky believes that the true goal of the campaign is to assimilate the cars into a botnet. Some cars come with a SIM slot and are connected to the internet 24/7. It is probably not an exaggeration to say that cars just might be the perfect devices for a malicious botnet.
Kaspersky attributed the campaign to MoYu Group, a threat actor known for building malicious botnets based on Android devices. In the past, this group was observed building the BadBox botnet out of Android smartphones, tablets, streaming devices, and other internet-connected hardware.
The researchers notified DoFun of their findings, and the vulnerability was quickly fixed: “We notified the vendor about the distribution scheme, and they subsequently reported fixing the security issues,” the researchers said.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via The Record
![]()
The best antivirus for all budgets

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Kaspersky found Android malware abusing DoFun car head units via TWCore updates Multi‑stage attack installs loaders and reverse proxy, aiming to build a botnet of connected cars Campaign attributed to MoYu Group; DoFun patched vulnerabilities after disclosure We’ve seen botnets comprising cameras and DVRs, we’ve even seen botnets comprising smart…
Recent Posts
- The RAMpocalypse has led global PC shipments to drop 20 percent in just 12 months
- An Anthropic model submitted a false homicide tip to Philadelphia police
- Ohio blogger found guilty of harassment for sending Shrek nude to senator
- MSI Pro Max Edge AI+ mini PC review
- ‘Pure insanity’: Mathematicians will need years to make sense of OpenAI’s latest drop
Archives
- October 2026
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023