First Documented Android Malware Targets Automotive Head Units, Accelerating Ad Fraud Threats
In June 2026, researchers identified a new strain of malware specifically designed to target automotive head units running on the Android operating system. This malware installs itself like a standard user application but notably lacks a user interface, raising concerns about its potential to infiltrate devices without user consent. Subsequent investigations confirmed these suspicions, leading to a detailed reconstruction of the malware’s infection chain. This incident represents the first documented case of malware aimed at automotive head units, with objectives centered around ad fraud and the formation of a proxy botnet.
Key Findings from the Research
The research yielded several critical insights:
- A multi-stage downloader malware has been identified, specifically engineered for ad fraud and the establishment of a proxy botnet.
- The malware propagates through built-in updaters within the firmware of Android-based automotive head units.
- There is a high-confidence attribution of this malicious activity to the MoYu Group, a threat actor associated with the BADBOX botnet.
Kaspersky’s detection solutions have classified this malware under various identifiers, including HEUR:Trojan-Dropper.AndroidOS.Agent.vu and HEUR:Trojan-Downloader.AndroidOS.Agent.ov.
Understanding Automotive Head Unit Firmware
Automotive head units function as multimedia systems that also offer limited control over vehicle operations. These units can either be factory-installed or added as aftermarket enhancements. The primary attack vectors for these systems include physical access and vulnerabilities within the operating system or its components. Many automotive head units utilize the Android platform due to its adaptability, allowing manufacturers to tailor system applications for diverse functionalities.
Most Android applications, including malware, can operate on these head units. However, certain malware types, such as banking Trojans, are less inclined to target these systems due to the absence of valuable data. Instead, the malware uncovered in this research exploits the connectivity features of head units, such as SIM card slots and internet access, to recruit devices into a botnet, akin to attacks on Internet of Things (IoT) devices.
The Role of the TWCore App
The legitimate TWCore application is tasked with gathering analytics data and updating head unit software. It employs an MQTT message broker hosted on the subdomain cardoor[.]cn to relay messages regarding APK files that require downloading and installation. A significant aspect of this process is the installNotExists Boolean flag, which permits TWCore to install applications that are not originally present on the device.
Telemetry data indicated that the malware was consistently installed via an application with the package name com.tw.core, establishing a direct connection to the TWCore application.
Stages of Infection
Stage 1: The JarService Dropper
The initial stage features the JarService, a compact dropper application that operates without a user interface. It decrypts data embedded within the Trojan’s code, which is encrypted in blocks using a linear XOR key. This decrypted information contains crucial details about the payload version and entry point.
Stage 2: The Loader
The second stage introduces a malicious loader that executes the subsequent payload using reflection. It transmits device information to the attackers’ server via a POST request and receives a link to download the next payload in return.
Stage 3: Clicker / Reverse Proxy Loader
In the final stage, the malware sends periodic requests to the command and control (C2) server, relaying device information and checking for configuration updates. The C2 server can issue commands that enable the malware to display ads, engage in ad fraud, and download additional malicious code.
Attribution to MoYu Group
An analysis of the malware’s infrastructure and naming conventions led researchers to attribute the activity to the MoYu Group, which is linked to the BADBOX malware platform. This attribution is bolstered by overlaps in network infrastructure and the identification of similar malicious components across various devices, including television set-top boxes.
For further details, you can read the full report by Kaspersky here.
Published on 2026-08-22 08:24:00 • By the Editorial Desk
For ongoing coverage and breaking updates, visit our Latest News section.

