A supply-chain attack against Android-based car head units used a legitimate DoFun system application to install malware, according to BleepingComputer, citing research from Kaspersky. The affected devices are generic Android head units used for in-car infotainment, navigation, and settings controls. Kaspersky attributed the operation to MoYu, a threat actor BleepingComputer says has previously been associated with the BadBox malware botnet. The researchers described the case as the first documented infection chain created specifically for targeted car head units. The reported target is DoFun, a Chinese automotive software, cloud services, and hardware provider owned by Shenzhen Driving Control Technology Co., Ltd. DoFun sells Android-based head units that operate as the central interface for a vehicle’s infotainment and related functions. BleepingComputer reports that Kaspersky found the activity in June, when researchers observed a rogue Android application package being downloaded from TWCore, a legitimate DoFun system app. TWCore receives instructions through an MQTT server hosted at cardoor[.]cn, according to the report. The malware is called JarService. Kaspersky’s analysis, as summarized by BleepingComputer, says the app has no user interface; once launched, it decrypts and executes a second-stage loader that contacts command-and-control infrastructure and downloads another encrypted payload. The final payload periodically sends device details to the operators, including the model, display resolution, Wi-Fi SSID, and MAC address, and retrieves commands. Kaspersky said the malware does not interfere with driving or critical vehicle control systems, and appears built for monetization through advertising fraud and proxy resale. The main module observed by researchers was a reverse-proxy component named “zhima,” which turns an infected head unit into a proxy botnet node, BleepingComputer reports. Researchers also saw web requests used for click-fraud activity. Kaspersky said it notified DoFun of the findings, and DoFun replied that it had resolved the problem. BleepingComputer said it contacted both Kaspersky and DoFun with questions about the initial compromise vector and planned to update its report if more information becomes available. Who benefits: The apparent beneficiaries are the malware operators, who can monetize infected head units as residential proxy nodes or through ad-fraud activity. Security vendors and device makers also gain a concrete case study for hardening update channels in embedded Android environments. Who's exposed: The exposed group is users and distributors of DoFun Android-based head units described in the Kaspersky findings. The provided reporting does not quantify how many devices were affected.