Malware Targets DoFun Automotive Software Updates, Compromising Android Head Units

Recent investigations have revealed that malware operators have exploited vulnerabilities in Android-based car infotainment systems, specifically through compromised software updates, effectively converting vehicles connected to the internet into nodes for a criminal proxy botnet. This alarming trend raises serious concerns regarding the cybersecurity of automotive technologies.
According to findings from Kaspersky, a prominent Russian cybersecurity firm, a multi-stage strain of Android malware has been identified, primarily affecting automotive software and hardware manufactured by the Chinese company DoFun. What captured the attention of the cybersecurity experts at Kaspersky was the unique behavior exhibited by the malware.
Kaspersky observed that the malware installs similarly to any standard user application but does not attempt to disguise itself as legitimate software. Notably, it operates without any user interface, which sets it apart from more conventional malware that generally seeks to hide its true intentions.
Instead of cloaking itself within the existing software of a head unit or masquerading as a user-oriented application, the malware employs a more insidious approach. It capitalizes on legitimate update functionalities embedded within Android firmware, allowing it to infiltrate systems without triggering user suspicion.
Researchers traced the path of infection back to an application known as TWCore, which is typically pre-installed on DoFun head units. By exploiting the application’s download functionality, threat actors managed to install a malicious dropper known as JarService onto the units, all without the users’ knowledge.
Once JarService is installed, it activates silently, since it lacks any visible interface. This dropper subsequently loads a second-stage payload, which then signals the attacker-controlled infrastructure to retrieve additional malicious code. The third-stage payload, referred to as “zhima” by researchers, is designed to engage in ad fraud and to convert compromised head units into reverse proxies.
The reverse proxy functionality allows cybercriminals to redirect internet traffic, creating the illusion that the data originates from the vehicle’s internet connection. Kaspersky points out that, while a car’s head unit typically does not hold high-value assets for attackers, employing ‘classic’ Android malware is a strategic move to recruit devices into a botnet, akin to previous attacks targeting Internet of Things (IoT) devices.
This incident marks a significant milestone, being the first recorded case of malware deliberately targeting an automotive head unit. Kaspersky has attributed the malicious activities to the MoYu Group, a threat actor closely linked to notorious campaigns such as Badbox and Badbox 2.0, which have previously targeted Android smartphones, streaming devices, tablets, and smart television applications. Collectively, these campaigns have reportedly infected over 1 million devices globally.
Initially uncovered by Human Security in 2023, the Badbox campaign went on to affect an additional 30,000 IoT devices but faced disruption in December 2024 thanks to the proactive interventions of Germany’s Federal Office for Information Security.
In response to the cyberthreat, Kaspersky took the initiative to inform DoFun about the malware scheme, prompting the company to implement a security fix through an infrastructure update. This highlights the critical importance of ongoing cybersecurity efforts in protecting modern vehicles, which increasingly rely on complex software functionalities as part of their infotainment systems.
The evolving nature of cyber threats, particularly in sectors as sensitive as automotive technology, underscores the necessity for manufacturers to remain vigilant and proactive in addressing vulnerabilities. As vehicles become ever more connected, the risks associated with cyberattacks will continue to grow, necessitating robust security measures and real-time updates to safeguard against potential exploitation.

