Malware Specifically Designed for Car Head Units Ensnared in Botnet
A disturbing trend has emerged in the world of cybersecurity, with researchers at Kaspersky discovering malware specifically designed to target car head units. This malicious software, linked to the notorious BadBox botnet, is a wake-up call for vehicle owners and manufacturers alike.
The malware was found on an aftermarket infotainment system made by Chinese company DoFun, which is widely used in China and other APAC countries. The attackers exploited a vulnerability in the system’s update distribution channel, allowing them to deliver stealthy malicious Android applications that served as droppers, loaders, clickers, and reverse-proxy loaders.
The malware supports nine commands, including those that enable its operators to display ads, conduct ad fraud, and download additional components. However, Kaspersky researchers have observed only commands related to downloading a reverse proxy module, suggesting that the main goal is to ensnare devices in a proxy botnet.
This development is particularly concerning as it marks a new front in the battle against cybercrime. BadBox has been around since at least 2023, enabling its operators to use hacked Android devices for fraud and other illicit schemes. The botnet’s growth has been exponential, with Google filing a lawsuit last year against its operators over concerns that more than 10 million Android devices had been compromised.
What’s most alarming is that BadBox malware is often pre-installed on budget devices, but attacks targeting vehicle infotainment systems show that its operators are expanding their delivery methods and targets. This suggests that the threat landscape is evolving rapidly, with cybercriminals adapting to new technologies and vulnerabilities.
The link between this malware and the BadBox botnet has led researchers to strongly believe that the MoYu Group is behind it. The MoYu Group is one of several entities previously linked to the development and operation of BadBox.
This incident highlights the importance of staying vigilant when it comes to vehicle security. With more cars on the road than ever before, the potential for damage from a cyber attack is significant. Manufacturers must prioritize the security of their systems, while owners should be aware of the risks and take steps to protect themselves.
One takeaway from this incident is that cybersecurity is not just an IT problem; it’s a societal issue that requires cooperation between manufacturers, owners, and law enforcement. By working together, we can mitigate these threats and keep our vehicles safe from cyber attacks.
As the world becomes increasingly dependent on technology, it’s essential to address these emerging threats proactively. By doing so, we can prevent more severe consequences and ensure a safer digital landscape for everyone.
Source: SecurityWeek — 2026-08-25