
The infotainment unit in our cars usually runs its own operating system specific to the car maker. However, some aftermarket models might run on an Android-based system. If you do have such a system in your vehicle, you might want to watch out for the BotNet malware that infects Android car head units.
What the BotNet Android car malware does
Kaspersky researchers first spotted the campaign in June 2026 while tracking Android threats. They found an app called JarService installed on some units. However, it had no interface and made no attempt to look legitimate. That’s usually a sign a user didn’t install it themselves.
The affected units come from DoFun, a Chinese company that builds generic Android-based head units. Once installed, JarService quietly downloads a second piece of software called “zhima.” Zhima then turns the head unit into a reverse proxy. This means that it lets the attacker route other people’s internet traffic through your car’s connection without you ever noticing.
The unit also fires off background web requests for ad fraud. It cashes in every time it “views” an ad nobody in the car actually saw. According to Kaspersky, this Android car botnet malware doesn’t touch anything tied to driving or vehicle safety. Its only job is turning your dashboard into a quiet moneymaker for someone else. So you don’t have to worry about it suddenly taking control of your vehicle or steering you off the road.
A little tricky to stop
Most of the time when it comes to malware, protecting yourself is relatively easy. You just follow a few good practices, like not downloading from sketchy sources, opening random links or email attachments, those sorts of things.
However, the researchers tie the campaign to MoYu Group, the same operation behind BadBox. For those unfamiliar, it’s a malware family that’s shown up on TV boxes and other budget devices more than once.
It doesn’t arrive through some sketchy app download or shady link. It rides in through the head unit’s own built-in update system. That’s the exact channel that’s supposed to keep your dashboard safe in the first place.
Kaspersky reported its findings to DoFun, and the company says it’s already fixed the issue. Unfortunately, there’s still no simple way for a driver to check whether their own unit was ever affected.
The post Your Car’s Android Head Unit Could Be Quietly Running a Botnet appeared first on Android Headlines.