← BACK TO FEED
TAG

android malware5 articles

BadBox Botnet Comes for Your Car: First Malware Targeting Vehicle Head Units Discovered

Kaspersky researchers have discovered what appears to be the first malware specifically designed for car head units, found on Android-powered infotainment systems made by Chinese company DoFun. The malware was delivered by exploiting a vulnerability in the device's software update system, and is believed to be the work of the MoYu Group, a threat actor linked to the BadBox botnet. The attack suggests that BadBox operators are expanding beyond budget TV boxes and Android devices, now targeting vehicle infotainment systems to ensnare them in a proxy botnet used for ad fraud and other illegal schemes.

26 Aug 2026

Your Car's Infotainment System Is Now a Botnet Node, Apparently

Kaspersky researchers have discovered a new malware family targeting Android-based car head units, marking the first documented case of malware using an infection chain specifically designed for vehicle systems. The malware, attributed to the MoYu Group, spreads through the legitimate built-in software update mechanism of DoFun firmware, deploying a multi-stage downloader that enables ad fraud and recruits devices into a proxy botnet. The threat highlights the growing security risks posed by internet-connected automotive platforms, as the infected head units' SIM card slots and Android compatibility make them increasingly attractive targets for cybercriminals.

24 Aug 2026

Flying Eagle Android RAT Source Code Leaks, Fingerprints Spotted on 170 Servers

Source code for the Flying Eagle Android RAT framework is circulating on criminal Telegram channels, with researchers at Hunt.io and NetAskari identifying matching infrastructure on 170 internet servers, though this figure reflects server fingerprints rather than confirmed victims or active command-and-control systems. The toolkit, disguised as a fake Chinese public security app, supports keystroke and payment-password capture, screen recording, camera access, and phishing overlays, and its builder generates obfuscated APKs with encrypted C2 URLs. Researchers also identified a separate Android RAT called Night Dragon being promoted by one of the same Telegram channels, though it appears to be an independent, financially motivated tool unrelated to the 2011 espionage campaign of the same name.

29 Jul 2026

Google and FBI Knock Out NetNut Proxy Network Backed by Millions of Infected Devices

Google, the FBI, and other partners disrupted NetNut (also known as Popa), a residential proxy network comprising over 2 million infected Android devices, including smart TVs and streaming boxes compromised through malicious apps. The network, linked to Israeli firm Alarum Technologies, rented proxy access to cybercriminals and espionage groups, with 316 distinct threat clusters observed using it in a single week. Google's actions included disabling associated accounts, dismantling backend infrastructure, and removing infected apps via Google Play Protect, resulting in a significant reduction in the botnet's available devices.

15 Jul 2026

NFCShare Malware Evolves: Fake Banking App Updates Delivered Via GitHub

A new Android malware called NFCShare is being distributed through fake banking app updates hosted on GitHub, targeting customers of banks primarily in Italy and Spain. The malware tricks victims into scanning their payment cards near their phone's NFC chip under the guise of a security verification, stealing card details and PINs which are then sent to attackers for use in NFC payment relay fraud. Android users are advised to only download banking apps from Google Play, enable Play Protect, and be wary of any requests to scan their cards through an app.

10 Jun 2026