Hackers Infect Android Car Head Units with Proxy Botnet Malware
Hackers use legitimate app to spread malware targeting Android car head units. Kaspersky notes first documented case of malware specifically for car head units.
Intelligence analysis by Qwen 2.5 (3B)

Hackers exploit legitimate app to spread malware targeting Android car head units, turning them into proxy nodes for ad fraud or residential proxy use.
Hackers tricked a legitimate app to spread malware in cars. The malware turns the car's screen into a middleman for ads or lets hackers use the car as a home computer.
Analysis
{"heading_1":"Supply-Chain Attack Details","paragraph_1":"Kaspersky notified DoFun of the findings, and the Chinese firm reported resolving the problem. However, the initial compromise vector remains unknown.","paragraph_2":"Once attackers have valid credentials, prevention drops sharply, with only 37% of actions blocked. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.","paragraph_3":"The final payload collects device information and executes commands, including HTTP requests, web browsing, and data exfiltration. The malware does not interfere with critical vehicle systems.","heading_2":"MoYu Group's Operation","heading_3":"DoFun's Response"}
Key points
- Hackers use legitimate app to spread malware targeting Android car head units
- MoYu group is attributed to the operation
- The malware turns head units into proxy nodes for ad fraud or residential proxy use
- DoFun sells generic Android-based head units used for infotainment, navigation, and settings systems
- Once attackers have valid credentials, prevention drops sharply
With better security measures, the malware could be stopped before it spreads further. Companies can improve their systems to prevent such attacks.
If the malware spreads, it could cause problems like fake ads or hackers using the car's internet connection for their own purposes.


