MoYu Group's BadBox Variant Targets DoFun Android Head Units via Compromised Update Channel
Kaspersky documented the initial malware built expressly for vehicle head units, delivered through a compromised DoFun Android update channel and tied to the MoYu-operated BadBox proxy botnet. The campaign extends prior TV-box tactics into automotive hardware, prioritizing stealthy enrollment over immediate fraud. Expansion into always-connected infotainment systems signals a broader supply-chain targeting pattern that existing automotive security models do not yet address.
The malware reached devices after operators subverted the vendor's software-update distribution path, pushing nine-command Android apps that function as droppers, loaders, clickers, and reverse-proxy loaders. Observed traffic shows only the proxy module activated, indicating the primary objective is enrollment into a residential and now mobile proxy network rather than immediate ad fraud on the vehicle screen. The affected hardware is an aftermarket Chinese unit sold across APAC, exposing a supply-chain vector that bypasses OEM security controls. Evidence from the sample set matches code patterns previously attributed to MoYu Group actors behind BadBox since 2023. Google’s 2024 civil complaint documented more than 10 million compromised Android TV boxes using similar pre-install and update-channel tactics; the head-unit samples extend that methodology to a new device class without requiring physical access or user interaction beyond normal OTA updates. This marks an operational expansion from static TV boxes into always-on automotive systems that remain powered and network-connected for extended periods. The pattern aligns with prior BadBox growth after law-enforcement takedown attempts, showing rapid re-tooling of delivery infrastructure rather than abandonment. Automotive aftermarket devices lack the patch cadence and attestation mechanisms found in OEM infotainment stacks, lowering the cost of sustained proxy operations. Next indicators to monitor include similar update-server compromises on other budget head-unit vendors and any shift from passive proxy use to active command-and-control that could affect vehicle telemetry or driver-facing functions.
SENTINEL: 5,000+ additional DoFun-family head units enrolled in BadBox within 90 days of disclosure
Sources (2)
- [1]Primary Source(https://www.securityweek.com/first-malware-built-specifically-for-car-head-units-fuels-botnet/)
- [2]Supporting Source(https://blog.google/threat-analysis-group/badbox-2-0-lawsuit/)