Kaspersky identifies first car head unit malware linked to BadBox botnet
Kaspersky researchers have identified the first malware specifically targeting Android-powered car infotainment systems, which is being used to facilitate ad fraud and botnet recruitment. The malware, linked to the BadBox botnet, exploits software update channels on aftermarket head units to deploy malicious components.
Key Takeaways
- Malware exploits vulnerabilities in software update channels on DoFun aftermarket head units to deploy stealthy droppers and loaders.
- Threat actors can execute nine distinct commands, including displaying unauthorized ads and downloading reverse proxy modules.
- Google previously filed a lawsuit against the operators of the related BadBox 2.0 botnet, which has infected over 10 million devices.
- The MoYu Group is the primary entity suspected of developing this specific infotainment-targeted variant.
Why It Matters
The discovery of car head unit malware signals a dangerous expansion of ad-fraud botnets into the automotive streaming and infotainment ecosystem. As vehicles increasingly rely on Android-based aftermarket hardware for media consumption, they become high-value targets for proxy recruitment and fraudulent ad impressions. This development forces a reassessment of security protocols for in-car entertainment systems, which often lack the rigorous update oversight found in smartphones. The industry must now account for the risk of compromised hardware impacting both user privacy and the integrity of ad-supported streaming metrics. Watch for whether Google or other OS providers implement stricter hardware certification requirements for third-party infotainment vendors to mitigate these supply chain vulnerabilities.
Additional Context
Kaspersky's discovery of car head unit malware represents the latest evolution of the BadBox botnet, which has grown substantially since its initial identification. In early 2025, Google's Threat Intelligence Group reported that BadBox had infected over 10 million Android devices globally, primarily through compromised cheap Android TV boxes and streaming sticks sold through unofficial channels. The botnet's operators monetize infected devices by routing them through residential proxy networks and generating fraudulent ad impressions, a model that now extends to vehicles equipped with vulnerable aftermarket infotainment hardware. DoFun, the head unit manufacturer implicated in this campaign, operates in a largely unregulated segment of the automotive aftermarket where security certifications remain voluntary.
The regulatory landscape around automotive cybersecurity is tightening, though enforcement mechanisms lag behind the threat. The United Nations Economic Commission for Europe's WP.29 regulation, which mandates cybersecurity management systems for new vehicle types sold in participating markets, began applying to all new vehicles registered in the EU from July 2024, but it covers OEM-installed systems rather than aftermarket units like those from DoFun. Meanwhile, the U.S. Federal Trade Commission has signaled increased scrutiny of connected-car data practices, launching a 6(b) study in January 2025 into how automakers and third-party device makers collect and share driver data. The gap between OEM security requirements and aftermarket device oversight creates the exact supply chain vulnerability that BadBox 2.0 exploits.
From a technical standpoint, the car head unit malware shares infrastructure and code patterns with earlier BadBox variants targeting streaming devices. Trend Micro researchers documented in March 2025 that BadBox 2.0 uses a modular payload delivery system that allows operators to swap between ad-fraud, proxy, and credential-theft modules depending on the infected device's capabilities. The automotive variant specifically abuses the over-the-air update mechanism built into Android-based head units, a channel that Kaspersky noted lacks the code-signing verification present in Google's certified Android Automotive OS. Google's Android Automotive OS, which powers factory-installed systems in vehicles from General Motors, Volvo, and Polestar, requires hardware attestation and verified boot as part of its compatibility requirements, protections entirely absent from the uncertified aftermarket units targeted in this campaign.
Read full article at securityweek.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source