BADBOX-Linked MoYu Hackers Abuse Android Car Head Unit Updates to Build Proxy Botnet
Brief
Security researchers have uncovered the first documented malware campaign specifically targeting Android-based automotive head units, attributing the operation with high confidence to MoYu Group, a threat actor tied to the notorious BADBOX botnet.
The discovery marks a significant escalation as botnet operators expand beyond smartphones, smart TVs, and set-top boxes into in-vehicle infotainment systems, echoing trends seen in other covert malware campaigns infiltrating connected smart hardware.
BADBOX-Linked MoYu Hackers Build Android Proxy Botnet
While monitoring Android threats in June 2026, researchers flagged a suspicious application that installed like a normal user app but had no user interface whatsoever, a red flag suggesting it was reaching devices without user consent, according to Kaspersky’s Securelist research report .
