The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 07:58 am AEST · 24 August 2026

28 DAYS AGO Key event Share

Hackers use car software update to plant proxy botnet malware on Android head units

Hackers use car software update to plant proxy botnet malware on Android head units
Photograph: BleepingComputer

Hackers have infected Android-based car head units with malware that turns the devices into proxy botnet nodes for monetization, Kaspersky researchers said on Thursday. The attack uses a legitimate software-update app from DoFun, a Chinese automotive provider, to download malicious code that establishes contact with attacker-controlled servers and supports nine commands including web requests and arbitrary code execution.

Kaspersky attributed the operation to the MoYu group, previously linked to the BadBox botnet, and said it represents the first documented malware infection chain targeting car head units. The malware does not interfere with driving or critical vehicle systems but appears designed for advertising fraud and turning internet-connected units into residential proxy nodes. Kaspersky notified DoFun, which said it had resolved the problem, Bill Toulas reports for BleepingComputer.

Hackers infect Android car head units with proxy botnet malware A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. bleepingcomputer.com
cybersecuritymalwareandroidbotnets

Follow the live coverage →

Hackers use car software update to plant proxy botnet malware on Android head units | The Financial Register Inward Money