Hackers Target Android Connected Car Head Units to Build Ad-Fraud Botnet
Cybersecurity researchers at Kaspersky uncovered a campaign that hijacked firmware updates on vehicle infotainment systems manufactured by DoFun.

Cyberattacks targeting connected vehicle infrastructure have expanded into automotive infotainment systems, as security researchers uncovered a malware campaign infecting in-car head units to recruit them into ad-fraud botnets. The campaign, first reported by TechRadar Pro, marks the first documented instance of malicious code engineered specifically to compromise this vehicle hardware supply chain.
According to research published by cybersecurity firm Kaspersky, the attack vector leverages compromised update mechanisms in Android-based head units manufactured by hardware vendor DoFun. Threat actors hijacked TWCore, an authentic pre-installed system application designed to collect telemetry and deliver remote software upgrades, utilizing a specialized dropper utility named JarService to deploy previously unidentified payloads onto vulnerable hardware.
Security analysts at Kaspersky attributed the infrastructure and operational tactics behind the breach to MoYu Group. The threat entity is closely associated with BadBox, a notorious ad-fraud botnet known for compromising millions of consumer electronics—including smart televisions, streaming set-top boxes, smartphones, and tablets—often before the hardware leaves manufacturing facilities.
Once deployed on a head unit, the malicious software operates stealthily as a background process without triggering any graphical user interface. Analysts identified nine separate command structures embedded within the malware designed to trigger ad fraud schemes and generate unauthorized revenue by displaying invisible advertisements.
Alongside executing ad-generation scripts, the malware systematically gathered granular telemetry from host vehicles. Exfiltrated data points included screen resolution parameters, specific vehicle hardware model numbers, active Wi-Fi network identifiers, and media access control addresses.
Investigating the underlying command-and-control network, Kaspersky researchers discovered operational links connecting the head unit campaign to prior exploits against smart television streaming boxes. The administration dashboards governing the botnet embedded links pointing directly to residential proxy marketplaces, specifically PXYEDGE and ProxyForU, which allow threat actors to route illicit traffic through legitimate consumer internet connections.
Car head units, which manage multimedia functions and in certain vehicle models interface directly with core automobile control systems, have become popular targets due to widespread architectural standardization. Automotive original equipment manufacturers and aftermarket suppliers frequently build these dashboards on the Android operating system to streamline interface customization and software integration, inadvertently exposing the hardware to standard Android threat vectors.
Although in-vehicle entertainment units rarely store sensitive personal financial records or credentials, their hardware configurations present ideal conditions for botnet operators. Modern head units regularly feature cellular SIM card slots and maintain persistent wireless network connections to support live satellite navigation and over-the-air software updates, coupled with historically light security monitoring compared to enterprise servers or personal computers.
Kaspersky confirmed that it alerted DoFun to the exploitation of its legitimate update and distribution channels. In response, DoFun reported that it has addressed and resolved the underlying vulnerability across the majority of impacted devices active in the field, though the full global scale of the campaign and potential exposure across other automotive supply chains remains under investigation.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



