Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-23 ยท updated: 2026-08-23 ยท tags: [incident, malware, android, iot, automotive, botnet, ad-fraud] ยท confidence: high ยท severity: medium ยท affected_sectors: [technology, manufacturing] ยท au_impact: true

Kaspersky researchers documented a malware family infecting Android-based vehicle head unit firmware made by DoFun, spreading through the devices' own built-in updaters โ€” the first documented case of malware with an infection chain specific to car head units. Attributed with high confidence to the MoYu Group, the multi-stage downloader enables ad fraud and recruits infected units into a residential proxy botnet. The finding extends botnet economics into vehicle-adjacent consumer hardware that sits, largely unpatched, on home networks.

Australian angle

Android-based head units from budget Chinese SoC vendors such as DoFun are common in the Australian aftermarket and imported-vehicle fleet. Devices that phone home through built-in updaters sit inside home networks with no enterprise-grade containment.

Source