Kaspersky described malware that reached car head units through the update client
Kaspersky published research on a campaign against Android head units in which the unit's own legitimate update component installed the payload.
Kaspersky published research on August 21 describing a malware campaign against Android-based car head units, which it called the first whose infection chain was built around automotive units rather than adapted from generic Android attacks. The company said it first observed the activity in June 2026.
The targets were head units sold under the DoFun brand, aftermarket devices that combine media playback with some vehicle functions. The delivery route was the update mechanism itself: a system application named TWCore accepted instructions over MQTT from a remote server, and a flag in those instructions allowed it to install applications that had never been present on the device. Kaspersky traced a three-stage chain from a dropper with no user interface, through an encrypted loader, to a module that enrolled the unit in a residential proxy network and generated fraudulent advertising traffic.
Kaspersky attributed the campaign to a group it tracks as MoYu, which researchers elsewhere have linked to earlier proxy-botnet schemes running on low-cost Android hardware. It published no estimate of how many units were infected.
The units concerned are fitted after sale rather than by manufacturers, so the research does not describe a compromise of any carmaker’s own software-defined vehicle platform. What it documents is the same Android base and the same update-client pattern that production cockpit software is built on, being used to install code the owner never chose.
Source: Kaspersky Securelist