- What: New malware targets Android car head units for ad fraud and botnet creation
- Impact: Vehicles with DoFun firmware may be compromised
IoT New malware targets Android car head units for ad fraud and botnet creation August 21, 2026 Share By SC Staff (Adobe Stock) As reported by The Hacker News, a new malware family has been identified that specifically targets Android-based vehicle head unit firmware developed by DoFun, aiming to facilitate ad fraud and establish a proxy botnet. Kaspersky discovered the threat in June 2026, noting that the malware spreads through the built-in updaters of the head unit firmware. This marks the first documented instance of malware with an infection chain tailored for car head units. The activity is attributed to the MoYu Group, previously linked to the BADBOX botnet. The malware exploits a legitimate system app, TWCore, to deliver a dropper named JarService, which then launches a loader. This loader communicates with a command-and-control server to download further malicious modules. The malware supports commands for displaying ads, executing ad fraud, downloading additional malicious code, and gathering device information. It has been observed downloading a reverse proxy module known as "zhima." Source: The Hacker News SC Staff Related IoT Operation CameraSwarm compromises over 14,500 Dahua devices SC Staff August 20, 2026 The campaign, primarily impacting devices in Ukraine and Russia, leveraged CVE-2021-33044 and CVE-2021-33045, two authentication-bypass flaws rated 9.8 CVSS by the NVD. IoT Malicious SIM cards can take over cellular-connected devices SC Staff August 12, 2026 Researchers from the University of Birmingham and Fuzzware discovered that nine out of 26 tested devices, including several Quectel cellular modules and specific OPPO and ASUS phone models, were susceptible to use of the RUN AT command. IoT Zbtlink denies backdoor claims amid firmware download pause SC Staff August 7, 2026 VulnCheck CTO Jacob Baines claims that Zbtlink routers are intentionally designed to communicate with command and control servers, a feature he calls a "phone-home trojan horse." Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds