Malware Hijacks Android Car Update System for Ad Fraud and Proxy Botnet

Cybersecurity researchers have uncovered malware spreading through the built-in software update system of Android-based car head units, turning infected devices into tools for ad fraud and a proxy botnet.

Kaspersky discovered the campaign in June 2026 and described it as the first documented malware infection chain specifically designed to target automotive head units through their update system. The findings were disclosed on August 21.

A head unit is essentially a vehicle’s infotainment system, handling features such as navigation, music and other connected functions.

Malware Delivered Through Legitimate Updates

The campaign targets Android head units running software developed by DoFun. It does not affect all Android-powered vehicle systems.

According to Kaspersky, attackers abused a legitimate system application called TWCore, which normally handles analytics and software updates. By exploiting that trusted update channel, they were able to install malware on affected devices without requiring drivers to manually download a malicious app.

Once installed, the malware operates quietly in the background and downloads additional components.

Its main goals are ad fraud and recruiting infected car systems into a proxy botnet.

A proxy botnet allows criminals to route internet traffic through compromised devices, making that traffic appear to originate from the victim’s internet connection. In this case, connected vehicle systems effectively become another source of network infrastructure for attackers.

Kaspersky also found that the malware could collect information about infected systems, including the device model, display resolution, connected Wi-Fi network and MAC address.

The activity was attributed to a group linked to the BADBOX malware ecosystem previously associated with compromised Android devices such as TV boxes, smartphones and tablets secretly used for advertising fraud and proxy services. The new findings suggest operators connected to the scheme are expanding into automotive systems.

Researchers identified a reverse-proxy component known as zhima among the malware delivered to affected head units, further supporting the connection to proxy-botnet activity.

Kaspersky reported the software distribution abuse to DoFun and the security issue was subsequently addressed.

Attackers may not need to directly compromise a vehicle’s driving functions to profit from it. An always-connected infotainment system can itself be a security risk as they become more connected and increasily remember Android-powered devices.