← Blog · · df00tech

DoFun Android Car Head Units Targeted by New Malware for Ad Fraud and Proxy Botnet Operations

security-news campaign

What Happened

Kaspersky researchers reported discovering, in June 2026, a new malware family that specifically targets Android-based vehicle head unit firmware developed by DoFun. According to the report, the malware spreads through the firmware's built-in updater mechanism and deploys a multi-stage downloader whose end goals are ad fraud and the creation of a proxy botnet using compromised devices.

Why It Matters

In-vehicle infotainment (IVI) systems running Android are increasingly common, and this campaign highlights that automotive head units are being treated as just another class of exploitable Android endpoint. Because the infection vector is the firmware's own update mechanism, devices can be compromised through a channel users and fleet operators inherently trust, potentially at scale across any hardware or vehicles using DoFun-based head units. Compromised units repurposed as proxy nodes can also be leveraged to launder malicious traffic, complicating attribution and network defense elsewhere.

Who Is Affected

Based on the available reporting, exposure is tied to vehicles or aftermarket units running DoFun-developed Android head unit firmware. The full scope of affected models, vendors, or regions has not yet been detailed publicly.

What Defenders Should Watch For

  • Unexpected outbound connections or persistent background network activity from in-vehicle infotainment systems, consistent with proxy botnet or ad-fraud behavior.
  • Anomalous or unauthorized firmware update events on Android-based automotive head units, particularly ones not initiated by the legitimate OEM/vendor update channel.
  • Unusual app installation or downloader activity following an update event, which could indicate a multi-stage payload drop.
  • For fleet operators and automotive OEMs: verify the integrity and signing of firmware updater components, and monitor for firmware versions or update sources that deviate from known-good baselines.
  • General Android endpoint hygiene extended to embedded/IVI contexts: restrict unnecessary outbound connectivity, and audit installed packages where telemetry is available.

Note: no specific indicators of compromise, C2 infrastructure, or detection queries have been published in the source reporting as of this writing, so the above are high-level hunting angles rather than confirmed IOCs.

Developing Story

This is net-new intelligence from Kaspersky's research, surfaced here as a developing story rather than a fully mapped threat. Details on scope, affected firmware versions, and indicators may evolve as more information becomes public. For the original reporting, see The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.