← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 24, 2026 · 11:10via CyberPress

BADBOX-Linked MoYu Hackers Abuse Android Car Head Unit Updates to Build Proxy Botnet

Brief

Security researchers have uncovered the first documented malware campaign specifically targeting Android-based automotive head units, attributing the operation with high confidence to MoYu Group, a threat actor tied to the notorious BADBOX botnet.

The discovery marks a significant escalation as botnet operators expand beyond smartphones, smart TVs, and set-top boxes into in-vehicle infotainment systems, echoing trends seen in other covert malware campaigns infiltrating connected smart hardware.

BADBOX-Linked MoYu Hackers Build Android Proxy Botnet

While monitoring Android threats in June 2026, researchers flagged a suspicious application that installed like a normal user app but had no user interface whatsoever, a red flag suggesting it was reaching devices without user consent, according to Kaspersky’s Securelist research report .

Read more on CyberPress