Kaspersky finds malware built into Android car head unit firmware updaters
Kaspersky researchers discovered a new Android malware strain in June 2026 that spreads through the built-in update mechanisms of Android-based automotive head units, marking the first documented infection chain targeting this device category. The app installs silently with no interface, functioning as a multi-stage downloader designed for ad fraud and building a proxy botnet. Kaspersky attributes the campaign with high confidence to MoYu Group, an actor tied to the previously known BADBOX botnet.