Skip to content
Beveiligingsnieuws

Car Head Unit Malware: New Botnet Fuel

car head unit malware

Researchers at Kaspersky report what appears to be a breakthrough in mobile threats: car head unit malware designed specifically for aftermarket vehicle infotainment systems. The discovery also links the activity to the long-running BadBox botnet, raising concerns that attackers are extending botnet operations beyond TVs and other Android devices.

The affected environment is an Android-powered aftermarket infotainment unit made by the Chinese vendor DoFun. According to Kaspersky, the device is used in China and across parts of the APAC region, which increases the potential impact if malicious updates reach large numbers of cars.

Instead of relying on broad phishing or random app installs, the attackers focused on the vehicle’s software update pathway. That shift matters: once the update mechanism is compromised, malicious code can spread quietly and repeatedly.

Aftermarket infotainment and Android update risk

Kaspersky said the intrusion centered on a vulnerability in a component used to handle software updates. Threat actors exploited the weakness to deliver malware directly to the vehicle’s head unit. The vendor stated that it fixed the issue after being informed.

From a defender’s perspective, this is a familiar pattern but applied in a new way. Vehicle entertainment systems typically update through controlled channels, which users may assume are safer than downloading random apps. When that assumption breaks, the attack becomes far harder to notice.

BadBox connections and the update-channel takeover

The malicious delivery method was not a single app. Kaspersky observed that attackers compromised the update distribution channel to send stealthy Android applications to head units. These packages acted in multiple stages, including roles such as droppers, loaders, and click-related components, along with reverse-proxy loader capabilities.

By using a chain of components, the threat can reduce the chance that analysts or automated defenses will detect the full purpose of the malware early on. Each stage can collect the next task only after the previous one has completed.

What the car head unit malware can do

In the malware’s observed functionality, Kaspersky described support for nine commands. Those commands included actions that could help operators generate revenue through ads, perform ad fraud using the clicker component, and retrieve additional components for expansion or persistence.

Interestingly, Kaspersky also reported that it mainly saw commands related to downloading a reverse proxy module. That observation suggests the malware’s primary objective may be to trap devices within a proxy botnet infrastructure.

Why reverse-proxy behavior matters

A reverse-proxy setup can be valuable to cybercriminal operations because it can hide or route traffic through compromised devices. In practice, that can support additional abuse such as anonymized hosting, command-and-control routing, or traffic laundering, depending on how the broader botnet is managed.

When car head unit malware focuses on proxy capabilities, it indicates a strategic motive: expanding the pool of reachable systems that can be used as infrastructure, not just harvesting data or showing unwanted ads.

Attribution to the MoYu Group behind BadBox

After further analysis, Kaspersky stated it had strong grounds to believe the malware is the work of the MoYu Group, an entity previously associated with the development and operation of the BadBox botnet.

BadBox has reportedly been active since at least 2023. It has enabled operators to use compromised Android devices for fraud and other illegal schemes.

BadBox’s scale and the shift toward new targets

While law enforcement has attempted to disrupt BadBox, the threat has reportedly grown rapidly. Kaspersky referenced legal action as well: Google filed a lawsuit against BadBox 2.0 operators, warning that the botnet had ensnared more than 10 million Android devices, mainly TV boxes.

BadBox malware is often found pre-installed on lower-cost devices, but Kaspersky’s findings show a different trend. Attacks that target vehicle infotainment systems indicate that botnet operators are looking to expand their delivery methods and broaden their target base.

From TVs to vehicles: expanding the botnet surface

Car head units create a new attack surface for botnet builders. These systems can remain powered for long periods, may be connected to networks used by the household or vehicle environment, and can receive updates over time.

Even if only a subset of vehicles use affected configurations, the move demonstrates adaptability. It also suggests that future campaigns could target other Android-based in-car components beyond infotainment, especially when update mechanisms are present.

What to do if you maintain vehicle infotainment systems

For fleet operators, integrators, and developers working with aftermarket systems, Kaspersky’s findings underline a key security priority: protect the software update pathway.

  • Patch and verify update-handling components: if a vulnerability is identified, ensure it is fully addressed and not just mitigated.
  • Harden update distribution: limit who can publish updates and strengthen controls around update delivery.
  • Monitor for unusual update packages: look for unexpected app behavior patterns, staged installers, and suspicious network activity.
  • Review device telemetry: detect early signs of proxy module downloads and related command execution.
  • Communicate fixes promptly: Kaspersky noted the vendor said it corrected the weakness after notification, which is essential for reducing window of exposure.

Even when the wider threat landscape is complicated, focusing on update integrity can reduce the odds that car head unit malware ends up installed at scale.

Conclusion

Kaspersky’s discovery highlights how Android-based vehicle systems are becoming part of mainstream cybercrime infrastructure. The car head unit malware observed in the DoFun infotainment ecosystem appears tied to the BadBox botnet and was delivered through a compromised update distribution channel.

With the malware’s observed emphasis on reverse-proxy module deployment and its broader ad-fraud capable design, the campaign reflects both financial and operational goals. As botnet operators expand from traditional Android devices into vehicles, maintaining secure update processes may be one of the most effective steps to prevent future infections.

Source: https://www.securityweek.com/first-malware-built-specifically-for-car-head-units-fuels-botnet/