Kaspersky researchers have come across what appears to be the first malware specifically designed for car head units, and have found links to the notorious BadBox botnet.
BADBOX
BADBOX is an Android malware and botnet ecosystem associated with large-scale compromise of consumer devices, especially low-cost Android-based products such as TV boxes, tablets, smartphones, smart TVs, digital media devices, picture frames, and aftermarket automotive head units.
Profile source: Mallory opens in a new tabBADBOX
Family profile
BADBOX is an Android malware and botnet ecosystem associated with large-scale compromise of consumer devices, especially low-cost Android-based products such as TV boxes, tablets, smartphones, smart TVs, digital media devices, picture frames, and aftermarket automotive head units. The operation has been linked to the MoYu Group and is notable for supply-chain-style distribution, including firmware backdoors present before sale, as well as later campaigns that abused legitimate update mechanisms to silently install malicious applications.
BADBOX has been described as a global network of compromised Android devices used for covert monetization and criminal infrastructure. Reported capabilities include downloading and installing additional malware, collecting device and network information, enabling remote tasking, conducting ad fraud and click fraud, and converting infected devices into residential or reverse-proxy nodes that relay third-party traffic. Earlier reporting also tied BADBOX to account abuse and interception of one-time passwords on some infected Android devices. The ecosystem has been associated with proxy services such as PXYEDGE and ProxyForU.
A notable 2026 evolution targeted Android-based DoFun automotive head units through the legitimate TWCore updater path, in what was described as the first documented malware infection chain specifically built for car head units. In that campaign, attackers abused the built-in update workflow to deliver a multi-stage Android malware chain including a dropper known as JarService, a loader, and a final payload that supported ad-fraud activity and deployment of the zhima reverse-proxy module. Observed operator activity primarily involved loading the proxy component, indicating an objective of enrolling devices into a proxy botnet rather than interfering with vehicle control systems.
BADBOX has also been linked to firmware-level compromise resembling Triada-derived backdoor behavior on Android devices, allowing persistence and post-sale activation when devices first connect to the internet. The operation has survived multiple disruption efforts and has been observed at substantial scale, with reporting over time describing tens of thousands to millions of affected devices depending on campaign phase and measurement method. The malware primarily targets Android-based consumer and embedded devices and represents a persistent supply-chain and post-sale abuse threat focused on fraud, proxy monetization, and follow-on payload delivery.
Capabilities
- Defense Evasion
- Exfiltration
- Persistence
- Post Exploitation
- Process Injection
- Spoofing
Reported operators
Threat actors
6 named in public reportingKaspersky researchers analyzed the malware and attributed the operation to the MoYu group, a threat actor previously associated with the BadBox malware botnet.
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
"Google filed a 'John Doe' lawsuit ... against ... the 'BadBox 2.0 Enterprise,' which Google described as a botnet of over ten million unsanctioned Android streaming devices engaged in advertising fraud."
MITRE ATT&CK