Independent Reviews
Unmarked devices beneath an abstract protected network canopy
Device Security Published 26 Aug 2026 5 min read3 sources

Android Car Head Units Hit by Proxy-Botnet Malware

Kaspersky says attackers abused a legitimate update channel in some DoFun-powered Android car head units to install malware for ad fraud and proxy traffic. DoFun told the researchers it fixed the security issues.

By VPN Rocks Editorial Team

The short version

What you need to know

  • Kaspersky documented malware delivered through TWCore, a legitimate updater in some DoFun-powered Android head units. The researchers say DoFun reported fixing the security issues after notification.
  • The observed malware could show ads, perform ad fraud, download more code and add a head unit to a reverse-proxy botnet. Kaspersky says the malware sent attacker infrastructure device details including model, display resolution, connected Wi-Fi identifier and MAC address.
  • This is not a claim that every Android car display is infected. Owners of an affected aftermarket unit should identify the manufacturer and firmware, seek an official update and avoid unverified firmware files. A VPN cannot remove malware already running on the head unit.

What did the researchers find?

Kaspersky says it discovered a multi-stage Android malware chain targeting car head units in June 2026. The affected systems in its research used software developed by DoFun, rather than Android automotive displays generally.

The chain began with TWCore, a legitimate system application used for analytics and software updates. According to the technical report, attackers abused its ability to install apps and delivered a dropper called JarService without requiring a driver to click a link or install an app manually. Kaspersky says it notified DoFun and that the vendor subsequently reported fixing the security issues.

What could the malware do?

Kaspersky found commands for displaying advertisements, generating fraudulent ad activity and downloading additional malicious code. The malware also sent device information to attacker infrastructure, including the display resolution, device model, connected Wi-Fi network identifier and MAC address.

The researchers observed a reverse-proxy module that could route somebody else's traffic through an infected head unit. That can consume connectivity and make outside activity appear to come from the car's internet connection. Kaspersky attributed the operation with high confidence to MoYu Group, an actor it links to the BADBOX malware platform; that attribution is the researcher's assessment, not an independently established identity.

What drivers can check now

Do not assume that an ordinary Android Auto or Android Automotive screen is affected. Check the exact head-unit brand, model, firmware provider and installed software, especially for an aftermarket display. Look for an official vendor security notice or firmware update and ask the installer or vehicle service provider whether the unit uses DoFun software.

Avoid firmware files, update apps and recovery packages from forums, adverts or unofficial download sites. If the display becomes unusually slow, consumes unexplained mobile data, shows persistent unwanted ads or installs unfamiliar apps, disconnect its optional data connection where safe and seek guidance from the manufacturer or a qualified installer. Do not factory-reset or flash the unit while driving, and preserve settings needed for vehicle functions.

Where a VPN helps — and where it does not

A reputable VPN can encrypt internet traffic from a supported device and reduce what a local network or internet provider can see. If a head unit supports a properly configured VPN, that may protect ordinary traffic travelling over an untrusted hotspot.

A consumer VPN cannot remove JarService or later payloads, repair an abused updater, verify firmware integrity or stop malware with device-level privileges from running. It may also be unsafe to treat a car display like a normal phone if it controls vehicle functions. The effective response is vendor remediation, trusted firmware and professional support for an affected unit.

VPN Rocks view

Connected-car security is no longer limited to speculative remote-control scenarios. An internet-connected display can be valuable to criminals simply because it has bandwidth, processing power and an IP address that can be resold as proxy capacity.

Manufacturers should authenticate update instructions and packages, restrict what updater services can install, publish supported versions and give owners a clear security-notification route. Drivers need precise model-level guidance, not a broad warning that makes every Android dashboard sound compromised.

Primary reading

Sources and further reading

We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.

Useful next steps