{"id":30828,"date":"2026-08-21T15:29:52","date_gmt":"2026-08-21T14:29:52","guid":{"rendered":"https:\/\/www.kaspersky.co.uk\/blog\/?p=30828"},"modified":"2026-08-21T15:29:52","modified_gmt":"2026-08-21T14:29:52","slug":"car-botnet-malware-for-head-units-with-android","status":"publish","type":"post","link":"https:\/\/www.kaspersky.co.uk\/blog\/car-botnet-malware-for-head-units-with-android\/30828\/","title":{"rendered":"Botnet on the road: the first trojan for car head units"},"content":{"rendered":"<p>In June 2026, we discovered an unusual new piece of malware targeting\u2026 Android-based car head units. This is the first documented case of malware being delivered to automotive head units via an automatic firmware-update service. We\u2019ve covered <a href=\"https:\/\/www.kaspersky.com\/blog\/tag\/cars\/\" target=\"_blank\" rel=\"noopener nofollow\">automotive cyber-incidents<\/a> many times before, but those were generally related either to data leaks in manufacturers\u2019 <a href=\"https:\/\/www.kaspersky.com\/blog\/tracking-and-hacking-kia-cars-via-internet\/52497\/\" target=\"_blank\" rel=\"noopener nofollow\">digital infrastructure<\/a>, or to security researchers\u2019 <a href=\"https:\/\/www.kaspersky.com\/blog\/perfektblue-bluetooth-car-hack\/54159\/\" target=\"_blank\" rel=\"noopener nofollow\">experiments<\/a>.<\/p>\n<p>This case, however, involves malware that cybercriminals are distributing <em>in the wild<\/em>. Their goals are ad fraud and creation of a proxy <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/botnet\/\" target=\"_blank\" rel=\"noopener\">botnet<\/a> made up of infected automotive head units. In this article, we explain what a head unit is, how exactly attackers infect these devices, and what this could mean for drivers.<\/p>\n<h2>What is a car head unit (HU)?<\/h2>\n<p>First, let\u2019s clarify what a car <a href=\"https:\/\/en.wikipedia.org\/wiki\/Automotive_head_unit\" target=\"_blank\" rel=\"noopener nofollow\">head unit<\/a> actually is. The term may sound technical, but in reality, most drivers interact with one every time they use their car. A head unit is the vehicle\u2019s infotainment system \u2014 usually centered around a display used to control navigation, music, and other vehicle functions. In modern cars, head units are often connected to the internet.<\/p>\n<p>Manufacturers frequently use Android as the operating system for their head units \u2014 in part for simplicity\u2019s sake: Android is designed to support automotive head-unit usage cases, bringing a number of advantages:<\/p>\n<ul>\n<li>extensive options for customizing the interface;<\/li>\n<li>easy app development;<\/li>\n<li>the ability to add one\u2019s own system apps and components;<\/li>\n<li>a large existing app ecosystem.<\/li>\n<\/ul>\n<p>However, those same advantages also create risks \u2014 because the apps involved may be malicious rather than legitimate. And that\u2019s what\u2019s happened here: using a malicious application, attackers have made cars part of a botnet. Here\u2019s how\u2026<\/p>\n<h2>How do attackers infect car head units, and what malware do they use?<\/h2>\n<p>First, it should be noted that this malware doesn\u2019t affect all head units, but those specifically using software developed by the Chinese company DoFun. The company develops firmware, applications, and cloud services for Android-based automotive infotainment systems and, according to its <a href=\"https:\/\/www.dofun.cc\/cloud\/index.html\" target=\"_blank\" rel=\"noopener nofollow\">website<\/a>, it serves more than 30 million vehicle owners worldwide.<\/p>\n<p>To deliver the malware to a car\u2019s infotainment system, the attackers use TWCore, a legitimate system app responsible for software updates on DoFun head units. Under normal circumstances, TWCore obtains information from the developer\u2019s cloud about files that need to be downloaded and installed on the device. These are primarily updates for software already installed on the head unit, but the same mechanism can be used to install entirely new apps. And this is precisely what the attackers exploit: they use TWCore to install JarService \u2014 a malicious <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/trojan-droppers\/\" target=\"_blank\" rel=\"noopener\">Trojan dropper<\/a> \u2014 on head units.<\/p>\n<p>JarService is essentially an \u201cempty\u201d application. That is, it has no user interface, and makes no attempt to impersonate a legitimate service. The lack of an interface makes perfect sense in this case: the attackers don\u2019t need to persuade the user to install the malware manually, and no user interaction whatsoever is required.<\/p>\n<p>The JarService code contains, in encrypted form, the next-stage payload, as well as information about its version and entry point. JarService\u2019s job is to decrypt this data and launch the next stage of the infection: a malicious downloader. Once launched, the downloader connects to the attackers\u2019 command-and-control (C2) server, and sends it information about the installed malware. In response, the server provides a link to the next-stage payload. The downloader retrieves the payload, decrypts it, and executes it.<\/p>\n<p>In this case, the malware installs what\u2019s known as a clicker \u2014a type of malware used to fraudulently inflate ad impressions. Once running, the malware regularly contacts the C2 server and sends it information about the infected device \u2014 including its model, screen resolution, MAC address, and details of the connected Wi-Fi network. In return, the malware can receive various commands from the attackers. For example, it can make HTTP requests and open web pages. But most importantly it can download and execute additional malicious code on the compromised car\u2019s infotainment system.<\/p>\n<p>Attackers use this capability to install a malicious module called <em>zhima<\/em>, which adds the infected head unit to a botnet. The resulting botnet powers a so-called <a href=\"https:\/\/www.kaspersky.com\/blog\/save-your-home-router-from-apt-residential-proxy\/53840\/#:~:text=How%20compromised%20routers%20are%20exploited\" target=\"_blank\" rel=\"noopener nofollow\">residential proxy<\/a> service, allowing attackers to route their traffic through infected devices when carrying out attacks and other malicious activity.<\/p>\n<h2>Who\u2019s behind the malware, and what are the attackers trying to achieve?<\/h2>\n<p>The attackers infect car head units with malware primarily to expand their botnet. An investigation by Kaspersky experts has found that the operation is associated with the <a href=\"https:\/\/www.kaspersky.com\/blog\/android-tv-botnet\/55799\/\" target=\"_blank\" rel=\"noopener nofollow\">BADBOX malicious platform<\/a> and, more specifically, with one of the threat actors linked to it: MoYu Group. Clues in the malware\u2019s code, along with overlaps with infrastructure previously attributed to MoYu Group, point to the group\u2019s involvement. BADBOX itself brings together a range of malicious activity centered on infecting Android devices and secretly exploiting their resources.<\/p>\n<p>The attackers then make money by monetizing access to resources that belong to other people. While investigating the botnet infrastructure, our experts discovered links between MoYu Group and the PXYEDGE and ProxyForU services, which offer residential proxy services. These services allow clients around the world to route their internet traffic through devices connected to the botnet, thereby accessing the internet using those devices\u2019 IP addresses. This suggests that infected car head units may already be being used as part of this infrastructure.<\/p>\n<h2>How does the malware affect users?<\/h2>\n<p>First and foremost, the malware consumes some of the head unit\u2019s computing resources. The additional load may cause the car\u2019s infotainment system to become slower or less stable. At the same time, the internet connection speed of the infected device is also very likely to decrease, as attackers may route significant amounts of traffic through it.<\/p>\n<p>It\u2019s also worth noting that the malware\u2019s capabilities are not limited to providing proxy functionality. It can receive commands from the attackers, and download and execute additional malicious code. As a result, the consequences of an infection may vary depending on what payload the botnet operators decide to install on the device.<\/p>\n<h2>Conclusion<\/h2>\n<p>This case demonstrates once again that attacks on all kinds of internet-connected devices \u2014 from TV set-top boxes to car infotainment systems \u2014 are not merely theoretical, but very much a reality. Attackers are constantly looking for new devices whose resources they can exploit for their own purposes, so malware protection now matters far beyond computers and smartphones.<\/p>\n<p>Our experts informed the developer about the malware distribution scheme they identified, after which the developer addressed the security issues that had been discovered.<\/p>\n<p>A full technical analysis of the malware is available on <a href=\"https:\/\/securelist.com\/android-head-unit-malware\/121106\/\" target=\"_blank\" rel=\"noopener\">Securelist<\/a>.<\/p>\n<blockquote><p>What other methods can attackers use to hack a car, and what risks do they pose to drivers? Read more in our posts:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/automotive-security-2025\/54562\/\" target=\"_blank\" rel=\"noopener nofollow\">Highway to\u2026 hacked: cyberthreats to connected cars<\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/perfektblue-bluetooth-car-hack\/54159\/\" target=\"_blank\" rel=\"noopener nofollow\">Car hacking via Bluetooth<\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/dashcam-hack-botnet-on-the-wheels\/54839\/\" target=\"_blank\" rel=\"noopener nofollow\">Botnets on wheels: the mass hacking of dashcams<\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/the-car-that-spied-on-you-carint\/55680\/\" target=\"_blank\" rel=\"noopener nofollow\">Is your car spying on you?<\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/car-manufacturers-silently-sell-user-telematics-data\/51245\/\" target=\"_blank\" rel=\"noopener nofollow\">I know how you drove last summer<\/a><\/li>\n<\/ul>\n<\/blockquote>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-geek\">\n","protected":false},"excerpt":{"rendered":"<p>Attackers have found yet another source of free computing resources: automotive head units. We take a look at the first malware specifically targeting cars for infection.<\/p>\n","protected":false},"author":2739,"featured_media":30829,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2026],"tags":[105,205,629,971,2227,36,529,3930,268],"class_list":["post-30828","post","type-post","status-publish","format-standard","has-post-thumbnail","category-threats","tag-android","tag-botnets","tag-cars","tag-connected-devices","tag-cyberattacks","tag-malware-2","tag-threats","tag-transportation","tag-vulnerabilities"],"hreflang":[{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/car-botnet-malware-for-head-units-with-android\/30828\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/car-botnet-malware-for-head-units-with-android\/30996\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/car-botnet-malware-for-head-units-with-android\/26022\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/car-botnet-malware-for-head-units-with-android\/42555\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/car-botnet-malware-for-head-units-with-android\/56296\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/car-botnet-malware-for-head-units-with-android\/30969\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/car-botnet-malware-for-head-units-with-android\/36491\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/car-botnet-malware-for-head-units-with-android\/36403\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.co.uk\/blog\/tag\/cars\/","name":"Cars"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/30828","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/users\/2739"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=30828"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/30828\/revisions"}],"predecessor-version":[{"id":30830,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/posts\/30828\/revisions\/30830"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/media\/30829"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=30828"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=30828"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=30828"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}