Skip to content
Tech News
← Back to articles

Malware infects Android-based automotive head unit firmware

read original more articles
Why This Matters

The discovery of malware infecting Android-based automotive head units highlights a new security vulnerability in connected vehicles, posing risks to both consumer safety and privacy. This incident underscores the importance of securing automotive firmware updates and the need for manufacturers to implement robust cybersecurity measures in vehicle systems.

Key Takeaways

While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. This led us to suspect the app might be reaching users’ devices without their knowledge. Further investigation confirmed that hypothesis and allowed us to reconstruct the entire infection chain.

Key findings:

We identified new Android malware: a multi-stage downloader whose ultimate purpose is ad fraud and creation of a proxy botnet.

The malware spread through the built-in updaters of Android-based automotive head unit firmware. This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.

We attribute this activity, with high confidence, to the MoYu Group, an actor linked to the BADBOX botnet.

Kaspersky solutions detect the threats described below under the following detection names:

HEUR:Trojan-Dropper.AndroidOS.Agent.vu

HEUR:Trojan-Downloader.AndroidOS.Agent.ov

HEUR:Trojan-Proxy.AndroidOS.Zhima.*

HEUR:Trojan.AndroidOS.Vo1d.*

... continue reading