Hackers infect Android car head units with proxy botnet malware

A growing number of Android car head units have been compromised by hackers who are using them to create a proxy botnet or engage in ad fraud. The attack, which has been attributed to the MoYu group, targets systems from DoFun, a Chinese automotive software and hardware provider owned by Shenzhen Driving Control Technology Co., Ltd.

The malware infection chain is particularly noteworthy because it specifically targets Android-based car head units, making it the first documented case of its kind. According to Kaspersky researchers, the attackers are using a legitimate device-update app called TWCore to spread the malware. Once installed, the malware downloads additional payloads from command-and-control servers, allowing the hackers to control the compromised devices.

The compromised devices are primarily being used for ad fraud and turning internet-connected car head units into residential proxy nodes for monetization purposes. The malware supports a range of commands, including sending HTTP requests, copying content to the clipboard, and executing arbitrary code or additional modules. Researchers have also discovered that the operator is loading a reverse-proxy module named ‘zhima,’ which turns the head unit into a proxy botnet node.

Fortunately, Kaspersky researchers have confirmed that the malware does not interfere with driving or critical vehicle control systems. However, this attack highlights the growing risk of supply-chain attacks in the automotive industry, where vulnerabilities can be exploited to compromise safety-critical systems. As more vehicles become connected to the internet, we can expect to see a rise in these types of attacks.

The fact that DoFun has already acknowledged and resolved the problem is a positive step forward. However, it remains unclear how the initial compromise vector occurred or whether other manufacturers are vulnerable to similar attacks. For now, car owners should be aware of this potential threat and keep their vehicle’s software up-to-date with legitimate updates only.

Ultimately, this attack serves as a reminder that even seemingly innocuous devices can be turned into botnet nodes or used for malicious purposes if not properly secured. As we continue to rely on connected technologies in our daily lives, it is essential to prioritize cybersecurity and take steps to prevent these types of attacks from occurring in the first place.

In practical terms, this means being cautious when installing software updates or apps on your vehicle’s head unit, only using legitimate sources, and keeping an eye out for suspicious behavior. By staying vigilant and taking proactive measures to secure our connected devices, we can reduce the risk of falling victim to these types of attacks.


Source: Bleeping Computer — 2026-08-22