Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Car Infotainment Malware Hijacks Android Head Units via Compromised OTA Updates, Building a Criminal Proxy Botnet

Kaspersky discovered Android‑based malware that infects DoFun car infotainment head units through a compromised OTA firmware update, turning vehicles into reverse‑proxy nodes for a large botnet. The incident underscores the importance of SOC 2 vendor‑risk and change‑management controls for organizations that rely on third‑party OTA updates.

LiveThreat™ Intelligence · 📅 August 26, 2026· 📰 databreachtoday.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
databreachtoday.com

Car Infotainment Malware Hijacks Android Head Units via Compromised OTA Updates, Building a Criminal Proxy Botnet

What Happened — Researchers at Kaspersky identified a multi‑stage Android malware family that infects infotainment head units on vehicles produced by Chinese OEM DoFun. The malware is delivered through a compromised over‑the‑air (OTA) software update, installs a hidden dropper, and ultimately turns the head unit into a reverse‑proxy node for a large‑scale ad‑fraud botnet.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a supply‑chain risk where a third‑party firmware provider can introduce malicious code into customer devices – a scenario SOC 2 vendor‑management controls (CC6.1) are designed to detect and mitigate.
  • Continuous monitoring of vendor‑provided updates becomes essential evidence that an organization is exercising due diligence and can produce a defensible audit trail.
  • Highlights the need for documented change‑control and integrity‑verification processes for IoT/OT updates, directly mapping to SOC 2 CC3.2 (change management) and CC7.1 (system operations).

Who Is Affected — Automotive manufacturers, Tier‑1 suppliers, IoT device makers, and any organization that distributes OTA firmware updates to connected vehicles.

Recommended Actions

  • Map the incident to SOC 2 vendor‑risk and change‑management controls; verify that DoFun’s update process is covered by your vendor‑assessment program.
  • Implement cryptographic signing and integrity verification for all OTA packages, and collect continuous evidence of successful verification as audit artifacts.
  • Initiate a third‑party risk review of DoFun, including security posture, patch‑management practices, and incident‑response capabilities.

Source: DataBreachToday

Technical Notes

  • Attack vector: Compromised OTA firmware update (third‑party dependency).
  • Malware stages: JarService dropper → second‑stage loader → “zhima” proxy/ad‑fraud module.
  • Data types: No direct data exfiltration reported; primary impact is device commandeering for proxy traffic.
  • Attribution: MoYu Group (linked to Badbox campaigns).

Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/car-infotainment-malware-builds-criminal-proxy-botnet-a-32652 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →