Hackers exploited trusted software updates to deliver malware directly into car head unitsKaspersky says this is the first campaign tailored specifically for vehicle head unitsThe malware can run silently without showing drivers any visible interfaceCar head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.Compromised update channels deliver malware straight into vehiclesResearchers believe the activity can likely be traced back to the MoYu Group, a threat actor closely tied to the well-known BadBox botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by DoFun.The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.Attackers hijacked this trusted update channel using a specialized dropper called JarService to deliver previously unknown malware directly onto a range of affected devices.Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device's MAC address.Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.The research team claims that the botnet's administration panel shares embedded URLs with residential proxy service websites PXYEDGE and ProxyForU.BadBox itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.According to statements from DoFun, the underlying issue has since been resolved across most affected devices currently deployed in the field.Head units present a growing and largely unprotected attack surfaceCar head units can arrive factory-installed directly from the manufacturer or get added later to older vehicles as aftermarket upgrades.Manufacturers frequently rely heavily on the Android operating system because it simplifies interface customization and essential system integration work considerably.This widespread industry reliance means most standard Android applications, along with most existing Android malware, can potentially run on these devices.Head units rarely store sensitive personal data directly on board, which on the surface might suggest only limited appeal to attackers.However, they typically include active SIM card slots and maintain constant internet connectivity for navigation services and routine software updates.That particular combination of persistent connectivity and comparatively weak security oversight makes these systems a genuinely attractive prospect for attackers going forward.The overall scale of this particular campaign remains genuinely unclear, and whether other head unit manufacturers face similar exposure is not yet known.