Modern infotainment systems increasingly resemble connected computers, and that also means they can attract the same kinds of threats. Security researchers have now documented malware being distributed to certain Android-based car head units in the wild.
According to Kaspersky, the malware was discovered in June 2026 and represents the first documented case of malicious software being delivered to automotive head units through an automatic firmware-update service. Unlike many previous automotive cybersecurity stories, this was not simply a controlled security experiment.
The campaign targets infotainment systems running software developed by Chinese company DoFun, which Kaspersky says provides firmware, applications, and cloud services for Android-based head units. The company serves more than 30 million vehicle owners worldwide, although Kaspersky did not suggest that every one of those devices was affected.
The malware is primarily designed to exploit the infotainment system’s computing power and internet connection. Researchers linked the campaign to ad fraud and a proxy botnet, effectively turning compromised car head units into remotely controlled internet-connected devices.
The Malware Arrived Through A Legitimate Update App

Kaspersky says attackers exploited TWCore, a legitimate system application responsible for delivering software to DoFun-based head units. Under normal circumstances, the app connects to the developer’s cloud infrastructure to download updates or install software.
Attackers used that mechanism to install a Trojan dropper called JarService without requiring any action from the driver. JarService contains encrypted code that launches another stage of the infection and connects with the attackers’ command-and-control infrastructure.
The malware can then retrieve and execute additional payloads. One of those is a so-called clicker, which can generate fraudulent advertising activity by opening web pages and making HTTP requests.
Infected Cars Can Become Part Of A Botnet
The malware also installs a component Kaspersky identifies as “zhima,” which can add the compromised head unit to a proxy botnet. That allows outside traffic to be routed through the infected device, effectively borrowing its internet connection and IP address.
Kaspersky linked the operation to the BADBOX malware platform and specifically to a threat actor known as MoYu Group. Researchers also found connections with residential proxy services PXYEDGE and ProxyForU, suggesting compromised devices may be used to provide proxy infrastructure to customers.
The malware collects information, including device model, screen resolution, MAC address, and details about connected Wi-Fi networks. Its ability to download and execute additional code means its potential capabilities are not necessarily limited to advertising fraud or proxy traffic.
Drivers Could Notice Slower Infotainment Performance

For drivers, the most immediate symptoms could be relatively mundane. Kaspersky says malware activity consumes computing resources and could make an infected infotainment system slower or less stable.
Network performance could also suffer if large amounts of outside traffic are routed through the vehicle’s connection. The larger concern is that attackers retain the ability to deliver additional malicious software, meaning the eventual impact could depend on whatever payload operators choose to deploy.
Kaspersky says it informed the software developer about the distribution method, and the security issues identified during the investigation were subsequently addressed.
