DoFun Updaters Smuggled Malware Into Car Head Units

Kaspersky said it found the first documented Android malware chain aimed at automotive head units, delivered through legitimate DoFun updater paths and attributed with high confidence to MoYu Group, a BADBOX-linked actor. The malware is a multi-stage downloader built for ad fraud and a proxy botnet, and it arrives as if it were a normal software update. The infection works because the malicious package rides the vendor’s own update mechanism, so the head unit accepts it through the trusted firmware flow instead of a separate app install. That means the vehicle can be enrolled without a user ever seeing a suspicious prompt, and cleanup aimed at apps alone can miss the channel that installed the payload in the first place. For operators of Android-based in-vehicle systems, the exposure is the trust placed in updater infrastructure: if that path can be abused, the device can be turned into persistent botnet infrastructure even when nothing obvious appears on the screen. Kaspersky’s finding also pushes the risk beyond a single model or app family, because any embedded system that silently trusts its update path inherits the same problem.

Part of the PlainSec briefing for 2026-08-21

Editions

Sources