Kaspersky has documented the first malware family purpose-built to infect Android-based vehicle head units, the dashboard computers that blend multimedia with partial vehicle control. The threat, found in June, spreads through the built-in updaters of head unit firmware developed by DoFun.
The malware is a multi-stage downloader designed to enable ad fraud and build a proxy botnet. Kaspersky ties the activity with high confidence to MoYu Group, the crew behind BADBOX, the sprawling ad fraud and residential proxy operation exposed last year. A related lawsuit followed in July 2025, with Google naming 25 unnamed defendants in China over the BADBOX operation.
Head units are attractive targets because they carry a SIM slot for navigation and updates, giving attackers an always-on internet connection inside the car. Kaspersky researcher Dmitry Kalinin notes delivery methods are becoming highly varied, from pre-installed backdoors to compromised IPTV apps. In this case, the infection exploited the legitimate software update function of a system app, the first documented infection chain specific to car head units.
Owners of aftermarket and factory Android dashboards should update firmware only from vendor sources and treat head units as networked devices worth isolating from critical vehicle systems.
