Tendvane

← All articles

SecurityAugust 23, 2026

Someone put malware in a car stereo, and it's renting out the connection

Kaspersky published something on Friday that hadn't been recorded before: malware living on the Android screen bolted into a car dashboard. Not a lab demo or a conference stunt. Real head units, infected in the field, calling home.

The units run firmware from DoFun, a Chinese supplier whose software sits inside a lot of aftermarket dashboard screens. That firmware includes a system app called TWCore which handles analytics and software updates. It takes its orders from a message broker at cardoor.cn, which tells it exactly which APK files to fetch and install - and someone got into that channel. What came down was a dropper called JarService with no interface at all, then a loader, then a module named zhima.

zhima is a reverse proxy. It doesn't touch the car; Kaspersky is explicit that the malware "does not interfere with driving or critical vehicle control systems." What it does is turn the head unit into an exit point for somebody else's internet traffic, with click fraud on invisible ads running alongside. Someone buys that traffic as a "residential proxy," and it comes out of your car. The same zhima module has been seen before on cheap Android TV boxes, delivered through IPTV apps, and Kaspersky ties the operation to the MoYu group behind the BADBOX botnet. The infection was found in June; DoFun has since fixed how those updates are distributed.

Nobody clicked anything, and that's the lesson to carry home. The cheap Android gadget in the car, the streaming stick behind the TV, the box that plays channels - each one takes firmware from whoever built it, and you never see the handover. If you own one, update it. Tendvane's Network scan will at least show you every device currently sitting on your home Wi-Fi, which is usually a longer list than people expect.

Sources

Download Tendvane