← BACK TO FEED
BadBoxbotnetAndroid malwarevehicle securityinfotainment

BadBox Botnet Comes for Your Car: First Malware Targeting Vehicle Head Units Discovered

Kaspersky researchers have discovered what appears to be the first malware specifically designed for car head units, found on Android-powered infotainment systems made by Chinese company DoFun. The malware was delivered by exploiting a vulnerability in the device's software update system, and is believed to be the work of the MoYu Group, a threat actor linked to the BadBox botnet. The attack suggests that BadBox operators are expanding beyond budget TV boxes and Android devices, now targeting vehicle infotainment systems to ensnare them in a proxy botnet used for ad fraud and other illegal schemes.

Kaspersky researchers have found what looks like the first malware built specifically to target car infotainment systems, and it has links to the BadBox botnet operation.

The culprit was spotted on an Android-based aftermarket head unit made by Chinese manufacturer DoFun, a brand with a fairly wide footprint across China and the broader Asia-Pacific region. Attackers found a weakness in the device's software update mechanism and used it to quietly push malicious apps onto vehicles. DoFun has since patched the flaw after being notified.

The apps themselves covered the usual bases: droppers, loaders, clickers, and reverse-proxy loaders. The malware supports nine commands in total, giving operators the ability to serve ads, run click fraud, and pull down additional components. In practice, however, Kaspersky only observed commands being issued to deploy a reverse proxy module. The priority, it seems, is recruiting head units into a proxy botnet rather than bombarding drivers with dodgy pop-ups.

Kaspersky attributes the campaign with reasonable confidence to a group called MoYu, one of several actors previously tied to the development and running of BadBox.

BadBox has been a thorn in the side of security teams since at least 2023. The botnet gives its operators a pool of compromised Android devices to run fraud schemes through, and it has proven stubbornly difficult to kill. Law enforcement has taken swings at it, but the thing keeps growing. Google filed a lawsuit last year against those behind BadBox 2.0, by which point the botnet had reportedly absorbed more than 10 million Android devices, mostly cheap TV boxes.

The jump to vehicle infotainment systems is a notable shift. BadBox has traditionally spread through budget consumer hardware that arrives pre-infected straight from the supply chain. Actively targeting car head units suggests the operators are branching out, looking for new categories of device to absorb. A head unit running quietly in someone's car, permanently connected to a mobile data connection, is a pretty appealing addition to a proxy botnet.

It probably won't be the last automotive target.

READ NEXT
Your Car's Infotainment System Is Now a Botnet Node, ApparentlyGoogle and FBI Knock Out NetNut Proxy Network Backed by Millions of Infected DevicesFlying Eagle Android RAT Source Code Leaks, Fingerprints Spotted on 170 Servers