-
Hackers abused the TWCore update app to install malware on some DoFun Android car head units.
-
The malware can turn infected head units into proxy nodes and support ad fraud.
-
Kaspersky links the campaign with high confidence to MoYu, a group tied to the BadBox malware platform.

Hackers have found a new way to use cars in an online money-making scheme. Kaspersky researchers found malware that targets Android car head units. They found the campaign in June 2026 while tracking Android threats.
The malware does not appear to target the car’s brakes, steering, or other key driving systems. Instead, it uses the head unit’s internet link to run ad fraud and proxy traffic.
Kaspersky says this is the first known case of malware with an attack chain made for car head units.
A Trusted Update App Helped Deliver the Malware
The campaign targets head units that use DoFun software. Some head units can connect to the internet through SIM cards. That makes them useful to criminals who want to build botnets.
The attack starts with TWCore, a real system app. TWCore collects data and updates software on the head unit. TWCore gets update orders through an MQTT message broker on a cardoor[.]cn subdomain. The orders tell the app which APK files to download and install.
Kaspersky found a setting called “installNotExists.” When this setting allows new apps, TWCore can install an app that was not on the device.
The attackers used this feature to deliver JarService. Kaspersky found the malware in TWCore’s download path and linked its install to the TWCore package. The attack did not need a driver to download a fake app. The trusted update process did the work.
JarService Starts the Infection
JarService is a small malicious app with no user interface. A driver may see no sign that it has started. When JarService runs, it unlocks hidden data in its code. It then starts the next stage. That stage acts as a loader and sends information about the infected machine to a server controlled by the attackers.
The server sends back a link to another payload. Kaspersky found seven versions of this third-stage payload. The last module periodically reports to the attackers within every 90 minutes, by default. It sends information including the device model, screen resolution, Wi-Fi name, MAC address, and malware configuration.
Moreover, the malware can also receive commands. Kaspersky found nine commands in the versions it studied. The commands can read saved app data, change clipboard contents, make web requests, open web pages, open browser links, check network access, and download more code.
One command can download and run extra code. Another can make web requests.
The Goal is Proxy Traffic and Ad Fraud
Kaspersky found that the attackers used these commands to download a module called “zhima.”
Zhima works as a reverse proxy. In simple terms, it lets other internet traffic pass through the infected head unit.
That can turn a car’s internet link into part of a proxy network. Criminals can then use or sell that access as residential proxy traffic.
The attackers can also load web pages and perform fake ad activity. This can help them make money from online ads without the owner knowing.
Kaspersky says the evidence points to money making rather than direct control of the vehicle.
The FBI has actively disrupted proxy-based fraud schemes. In December 2025, the agency seized the domain web3adspanels.org, which was used by criminals to store stolen bank login credentials obtained through fake bank advertisements placed on Google and Bing. The scheme led to about $28 million in attempted losses and roughly $14.6 million in actual losses, with the FBI identifying at least 19 victims nationwide.
The attack can still use network bandwidth, device resources, and data about the head unit.
Kaspersky Links the Attack to MoYu
Kaspersky attributes the campaign to MoYu with high confidence. Researchers found code and naming clues that connect the malware to MoYu. They also found major overlaps between the campaign’s network setup and infrastructure linked to the group.
Kaspersky also linked zhima to research from Nokia Deepfield. That team found the same proxy malware on Android TV set-top boxes.
MoYu has links to the wider BadBox malware platform. BadBox has infected Android devices and helped criminals make money through ad fraud and proxy services. The campaign shows how this model can move to other connected devices.
DoFun Says It Fixed the Issue
Kaspersky stated in a press release that they notified DoFun after finding the attack. The company told the researchers that it fixed the security issues behind the malware delivery scheme.
Kaspersky did not publish a total number of infected head units or the campaign’s full reach. The research focuses on head units that use DoFun software. It does not show that every Android car system faces the same threat.
Still, the case highlights a wider security problem. Connected car systems often trust built-in update tools because those tools need special access.
If attackers can abuse that trust, they can install malware without asking a driver to click a bad link. Owners of affected Android head units should use official firmware updates. Vendors also need strong checks to ensure that only trusted software can reach the device.
As more cars connect to the internet, attackers have more reasons to target their software. This campaign shows that even a car’s entertainment screen can become part of a criminal network.