mediumMalware

DoFun Android Car Head Unit Malware (Ad Fraud/Proxy Botnet Downloader)

First seen Aug 22, 2026 · Updated Aug 22, 2026

androidiotautomotivead-fraudproxy-botnetsupply-chainfirmwaredownloader

Kaspersky discovered a malware family targeting Android-based vehicle head unit firmware developed by DoFun, which propagates via built-in firmware updaters. The malware deploys a multi-stage downloader used to conduct ad fraud and enlist infected devices into a proxy botnet.

Technical Analysis

The malware abuses the legitimate built-in update mechanism of DoFun-developed Android automotive head unit firmware to achieve initial infection, indicating either a compromised update server, signing process, or supply-chain insertion point upstream of the OEM/ODM. Once installed, it deploys a multi-stage downloader component that fetches additional payloads used for ad fraud (simulated ad clicks/impressions) and to register the device as a node in a proxy botnet, likely for anonymizing malicious traffic or reselling residential-style IP access. Because it targets embedded Android firmware rather than the Play Store distribution channel, standard mobile endpoint defenses and app vetting do not apply, making detection and remediation dependent on OEM firmware updates. There is no direct evidence this malware targets AI agent frameworks or LLM tooling, but organizations that operate fleets of embedded Android devices (including those running edge AI/agent workloads for telematics or in-vehicle assistants) could see compromised network egress points and proxy abuse degrade or mask malicious traffic originating from or transiting through agent-enabled infrastructure. No CVEs have been publicly assigned to this campaign as of the report.

Affected Systems

Android-based vehicle head unit devices running firmware developed by DoFun; devices using DoFun's built-in OTA/firmware updater mechanism

Indicators of Compromise

  • Not disclosed in available reporting (multi-stage downloader payloads referenced by Kaspersky, June 2026 discovery)

Remediation Steps

  1. 1

    Verify firmware provenance

    Audit vehicle head unit firmware for DoFun-developed components and confirm update sources are legitimate and cryptographically signed.

  2. 2

    Monitor network egress

    Inspect outbound traffic from in-vehicle infotainment systems for proxy-like behavior, unusual ad-network connections, or unexpected C2 patterns.

  3. 3

    Apply vendor patches

    Coordinate with OEMs/ODMs using DoFun firmware to obtain and deploy security patches or updater integrity fixes once available.

  4. 4

    Restrict updater trust

    Where possible, disable or restrict automatic firmware updates from unverified sources and require manual verification of update packages.

  5. 5

    Segment IoT/embedded devices

    Isolate vehicle telematics and infotainment networks from broader corporate or fleet management networks to limit lateral movement and proxy abuse.

Industries Most Exposed

automotivetransportationiotconsumer electronics

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.