The world’s first Android Auto trojan turns millions of car radios into a global botnet—experts sound the alarm

Ethan Collins
The world's first Android Auto trojan turns millions of car radios into a global botnet—experts sound the alarm 4

Editorial Note: Talk Android may contain affiliate links on some articles. If you make a purchase through these links, we will earn a commission at no extra cost to you. Learn more.

Imagine never touching your car’s infotainment system, only to find out it has been quietly serving cybercriminals halfway across the globe. That is exactly what happened to millions of drivers, according to new findings: a previously undetected Android-based trojan turned car head units into tools for a global botnet.

A Trojan Hidden in Your Car Radio

Researchers at Kaspersky have identified malware capable of infecting connected car radios produced by Chinese manufacturer DoFun, according to a report cited by Clubic. Once a device was infected, it became part of a botnet—a network of compromised machines—controlled by cybercriminals.

The attackers exploited automatic update mechanisms built into the infotainment systems. This process, designed to secure devices, required no driver action or approval; infections occurred silently, without users’ knowledge.

Far More Than a Simple Radio

Kaspersky spotted the vulnerability in June 2026, during routine monitoring of Android threats. This was reportedly the first known trojan designed specifically for these types of car head units, which are used around the world. DoFun, which develops the firmware, applications, and cloud services for these systems, claims its head units are present in 30 million vehicles globally.

Each DoFun head unit runs a full Android system with onboard memory and supports separate app installation. This functionality goes well beyond basic screen projection from a user’s smartphone via Android Auto.

The Vulnerable Update Process

A pre-installed app called TWCore handles system updates for DoFun devices, retrieving files from a server located in China. Normally, it downloads updates for pre-installed software, but the process can also be hijacked to install full applications. A parameter named installNotExists bypasses routine installation checks, letting files be installed without requiring user approval.

This opening allowed attackers to install an initial module named JarService—a hidden, interface-free application. Encrypted within its code was a payload for the next stage of the attack. JarService would then decrypt this payload and launch a downloader, which contacted a remote command-and-control server. The server supplied a second program, which gathered the device’s identifier, software version, and update package, then provided directions to download a third module called zhima.

Zhima communicated with the remote server every 90 minutes, executing up to nine different instructions identified by Kaspersky. The most common command enabled the attackers to download and execute arbitrary code on the infected device.

From Proxy Sales to Click Fraud

The zhima module then linked each compromised head unit to the PXYEDGE and ProxyForU platforms, which trade in access to residential proxy connections. These connections routed outside internet traffic through the infected devices, most often for advertising click fraud schemes.

A separate module was responsible for displaying ads and creating fake clicks, generating illicit revenue for the operators behind the campaign. For drivers, the main consequence was a slowdown of the device and reduced in-car internet speeds, as a portion of processing power and bandwidth was diverted for the botnet’s activities.

Kaspersky attributed the campaign with high confidence to the MoYu group. Researchers based this on shared infrastructure with Badbox—a cybercriminal platform known for targeting Android devices—and malware detected previously in set-top TV boxes. The link has been independently confirmed by Nokia Deepfield Emergency Response.

This was not an isolated issue. In June 2025, the FBI warned that the Badbox 2.0 botnet had infected over a million uncertified Android devices in 222 countries and territories, including car multimedia systems, smart TVs, and inexpensive tablets.

Major tech companies are also monitoring the rise of illicit residential proxy networks. On July 3, 2026, Google announced it had dismantled a network related to NetNut (also known as Popa), which had covertly conscripted about two million home devices into its operation. This was Google’s third takedown targeting such networks in a year, following prior actions against Badbox 2.0 and a network called IPIDEA.

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post
Boba Story Lid Recipes – 2026 5

Boba Story Lid Recipes – 2026