Kaspersky has found the first malware campaign built to infect Android car head units, exploiting update systems to power ad fraud and proxy botnets.

BADBOX-Linked Malware Turns Aftermarket Car Screens Into a Global Botnet

The420 Web Correspondent
5 Min Read

The infotainment screen bolted into millions of budget aftermarket car dashboards has quietly become the newest frontier in a sprawling global botnet operation. Cybersecurity researchers at Kaspersky have documented what they describe as the first known malware campaign built specifically to infect Android-based car head units, exploiting the very software update system meant to keep these devices secure.

Discovered in June 2026, the campaign targets automotive head units running firmware developed by DoFun, hijacking a legitimate update mechanism to silently plant malware capable of powering advertising fraud and a residential proxy network. For Indian drivers, many of whom rely on inexpensive aftermarket Android head units to modernise older vehicles rather than paying for factory-installed systems, the discovery lands squarely within a segment of the market that has expanded rapidly alongside the country’s used and budget car ecosystem.

A Trusted Update Channel, Turned Against Its Users

According to Kaspersky researcher Dmitry Kalinin, the infection chain begins with TWCore, a legitimate system application responsible for collecting analytics and delivering genuine software updates to affected head units. Attackers weaponised this trusted channel to deliver a dropper called JarService, which installs like an ordinary application but deliberately avoids any visible interface, a design choice that suggests the malware was never meant to be noticed by the vehicle’s owner in the first place.

Once active, JarService reports device information to an attacker-controlled server, which responds with instructions for downloading further malicious code. Researchers identified multiple versions of this payload circulating in the wild, indicating an actively maintained and evolving operation rather than a single static piece of malware.

Quiet Persistence, Loud Consequences

The installed malware checks in with its command-and-control server roughly every 90 minutes, reporting device details including display resolution, model information and connected Wi-Fi identifiers. Depending on the response received, it can execute a range of commands, from modifying clipboard contents and making unauthorised web requests to downloading additional code and executing JavaScript within the device.

Most significantly, researchers found the malware deploying a reverse proxy module named zhima, previously observed in unrelated campaigns targeting low-cost Android TV boxes used for IPTV streaming. Once active, this module effectively converts an infected car head unit into a node within a larger proxy network, allowing attackers to route their internet traffic through the device and obscure its true origin, all while the vehicle’s owner remains entirely unaware their dashboard has become part of someone else’s infrastructure.

Part of a Botnet Operation India Has Already Encountered

Kaspersky has attributed the campaign with high confidence to the MoYu Group, an actor previously linked to BADBOX, a much larger ad fraud and residential proxy ecosystem that has compromised uncertified Android devices worldwide, including streaming boxes, digital picture frames and, as this case demonstrates, automotive infotainment systems. Google filed a lawsuit in July 2025 against 25 unnamed individuals or entities in China over alleged involvement in operating BADBOX’s infrastructure, though researchers note the ecosystem has continued adapting and relaunching despite repeated disruption efforts by cybersecurity firms and law enforcement agencies internationally.

The affected DoFun-based head units have since had the underlying software distribution issue addressed following responsible disclosure by Kaspersky, though the broader vulnerability the case exposes remains unresolved industry-wide. As Android-based infotainment systems become increasingly standard, whether factory-installed or fitted aftermarket, their internet connectivity and reliance on third-party firmware updates are creating attack surfaces that automotive manufacturers and aftermarket suppliers have historically not been required to secure to the same standard as smartphones.

The case adds automotive head units to a growing list of everyday connected devices absorbed into ad fraud and proxy botnets, following earlier BADBOX-linked discoveries across smart TV boxes and other low-cost Android hardware. For Indian consumers weighing aftermarket infotainment upgrades, the episode is a reminder that unbranded, low-cost connected devices sourced through unofficial supply chains carry security risks that extend well beyond the functions they are marketed to perform, since a compromised device can silently serve an attacker’s purposes long before its owner notices anything unusual.

Stay Connected