TechNewsReel
Live

Android Car Infotainment Systems Hijacked for Proxy Botnet and Ad Fraud

A supply-chain attack targeting DoFun head units turns vehicle dashboards into residential proxy nodes.

TechNewsReel Newsroom · August 22, 2026

Hackers have compromised Android-based car head units to build a residential proxy botnet, marking a rare instance of malware specifically targeting automotive infotainment hardware. The attack leverages a supply-chain vulnerability to turn vehicle dashboards into tools for ad fraud and traffic masking.

The infection targeted head units provided by DoFun, a company owned by Shenzhen Driving Control Technology Co., Ltd. According to research from Kaspersky, the attack began with a legitimate system application called TWCore. This app was used to download a rogue APK known as JarService via an MQTT server located at cardoor[.]cn. Once installed, the malware deployed a module named 'zhima' to transform the infotainment systems into residential proxy nodes.

The Mechanics of the Attack

The malware is attributed to the MoYu group, the same threat actor linked to the BadBox botnet. The final payload is highly versatile, supporting nine distinct commands. These include the ability to make HTTP requests and execute JavaScript within WebViews. Most critically, the malware includes a 'loadlib2' function, which allows the attackers to download and install additional modules on the device remotely.

Android-based head units act as the central hub for a vehicle's navigation, settings, and entertainment. Because these devices maintain persistent internet connectivity but are frequently omitted from standard security audits, they provide an ideal environment for botnet operators. By routing traffic through these devices, attackers can use legitimate residential IP addresses to hide their activities or commit click fraud.

Industry Implications

While Kaspersky researchers noted that the malware does not interfere with driving or critical vehicle control systems, the breach reveals a significant gap in the automotive supply chain. The incident demonstrates that third-party software providers can serve as primary vectors for compromising vehicle hardware. The ability to execute arbitrary code via the 'loadlib2' command suggests that while the current goal is financial gain through ad fraud, the access could potentially be escalated in future attacks to target more sensitive systems.

What to Watch

This case is cited as the first documented instance of a malware infection chain created specifically for targeted car head units. As automotive manufacturers increasingly rely on third-party Android-based ecosystems for their dashboards, the industry must now address the security of the software supply chain. Future monitoring will likely focus on whether the MoYu group or similar actors attempt to pivot from passive proxy operations to active interference with vehicle functions.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.