Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Android Car Malware Exploits Update Systems

New Android Car Malware Exploits Update Systems

Posted on August 21, 2026 By CWS

Cybersecurity experts have identified a new malware strain targeting Android-based car head units, posing a significant threat to automotive security. Kaspersky researchers first detected this malware in June 2026, noting its function as a multi-stage downloader designed for ad fraud and proxy botnet creation.

Malware Targets Android Car Systems

This malicious software infiltrates systems through the built-in update mechanisms of Android car head unit firmware, particularly those developed by DoFun. According to security researcher Dmitry Kalinin, this marks the first documented instance of malware specifically tailored to infect car head units.

The MoYu Group, previously exposed by HUMAN Satori Threat Intelligence and Research, is believed to be behind this attack. This group is associated with the broader BADBOX ad fraud and proxy scheme, which led to a Google lawsuit in July 2025 against various unnamed entities in China.

Infection Through Software Update Exploitation

The malware exploits the update systems of Android automotive head units, which serve as multimedia and control hubs in vehicles. These systems, prevalent in both factory-installed and aftermarket settings, are increasingly targeted due to their internet connectivity capabilities.

Kalinin highlights the sophisticated delivery method employed, which involves the misuse of legitimate system app functionalities to distribute the malware. The update mechanism uses the MQTT message broker hosted on “cardoor[.]cn” to download APK files to the “/push/apk/” directory for installation.

The attackers utilize a dropper named JarService to deploy malware, which sends implant data to a server and retrieves further payloads. This operation allows the malware to run covertly, without a user interface, by communicating with a command-and-control (C2) server every 90 minutes.

Impact and Continued Threats

With the ability to execute nine distinct commands, the malware performs actions ranging from displaying ads to downloading additional malicious software. It can also gather detailed device information, making it a versatile tool for cybercriminals.

Despite efforts to dismantle the BADBOX network, individuals linked to it persist in their activities, affecting devices globally. The malware’s unique focus on car head units highlights the urgent need for enhanced security measures in modern automotive systems.

As this threat evolves, automotive manufacturers and cybersecurity professionals must prioritize robust defenses against such malware to protect vehicle systems from exploitation.

The Hacker News Tags:ad fraud, Android malware, automotive security, car security, Cybersecurity, DoFun firmware, malware threat, MoYu Group, proxy botnet, software updates

Post navigation

Previous Post: Chinese Cybercriminals Leverage AI for Web Server Exploits
Next Post: Advanced Phishing Toolkit Resists Password Changes

Related Posts

New Mirai Variant Targets TBK DVRs with CVE-2024-3721 New Mirai Variant Targets TBK DVRs with CVE-2024-3721 The Hacker News
AI Malware, Voice Bot Flaws, Crypto Laundering, IoT Attacks — and 20 More Stories AI Malware, Voice Bot Flaws, Crypto Laundering, IoT Attacks — and 20 More Stories The Hacker News
Massive Android Fraud Operations Uncovered: IconAds, Kaleidoscope, SMS Malware, NFC Scams Massive Android Fraud Operations Uncovered: IconAds, Kaleidoscope, SMS Malware, NFC Scams The Hacker News
Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider The Hacker News
Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks The Hacker News
ShapedPlugin WordPress Plugins Hit by Supply Chain Attack ShapedPlugin WordPress Plugins Hit by Supply Chain Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple Enhances macOS Disk Access Amid AI Concerns
  • GlassWorm Exploits VS Code Themes in Supply Chain Attack
  • RemoveMacAI Clears 12GB by Eliminating Apple AI Models
  • ClickFix Campaign Exploits Fake CAPTCHA for Malware
  • AI Exploit in Zammad Exposes Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple Enhances macOS Disk Access Amid AI Concerns
  • GlassWorm Exploits VS Code Themes in Supply Chain Attack
  • RemoveMacAI Clears 12GB by Eliminating Apple AI Models
  • ClickFix Campaign Exploits Fake CAPTCHA for Malware
  • AI Exploit in Zammad Exposes Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark