A Firmware Updater Becomes the Loader

Kaspersky researcher Dmitry Kalinin documented the first malware campaign built specifically around automotive head units, and its entry point is the update channel every owner trusts by default. A component called JarService acts as a loader: it abuses the built-in firmware-update mechanism on DoFun infotainment systems, made by Shenzhen Driving Control Technology, to push a second payload onto the device. Because the delivery path is the vendor's own update process, the malware arrives looking like routine maintenance rather than an attack.

Once JarService has a foothold, it installs a proxy and ad-fraud module named zhima. From that point the head unit is no longer only an infotainment screen; it is a small, always-connected computer running code its owner never approved and would have no easy way to see. The car's own internet connection, the one meant for maps, streaming, and diagnostics, becomes the resource being sold.

The Car Keeps Driving Because Nothing Safety-Critical Moves

The malware does not touch steering, braking, or any other safety-critical vehicle system, and that containment is deliberate rather than accidental. It rides entirely on the infotainment and connectivity layer, the part of the car built to talk to the internet, run apps, and accept updates. A driver gets no warning light, no drop in braking response, no reason to suspect anything, because nothing about how the car drives has changed.

That is precisely what makes a residential-proxy botnet attractive to whoever is running it. A compromised head unit that still works perfectly as a head unit is valuable for exactly as long as nobody notices it, and a car that never behaves unsafely gives its owner no reason to look, literally or figuratively, at what its network connection is doing in the background.

Individual Owners Barely Notice, Fleets and Dealerships Carry the Exposure

Individual owners are the least exposed party in this story, because a single compromised car is one node lost in a botnet of unknown size, and a slightly slower infotainment screen is easy to dismiss as ordinary wear. Fleet operators and dealerships carry the real exposure, since the same DoFun head unit, and the same firmware, sits behind the dashboard of every vehicle they source from that supplier. One compromised update means every car built on that platform is a candidate for the same infection, not just the unlucky unit that happened to get inspected.

A dealership that checked head-unit software once, at delivery, has no visibility into what changed on the tenth, twentieth, or hundredth over-the-air update since. A fleet operator managing hundreds of vehicles inherits that same blind spot at scale: the audit that felt sufficient on day one says nothing about the firmware running today.

BADBOX Already Had a Track Record Before It Had Wheels

BADBOX is not a new botnet invented for this campaign. HUMAN Security's Satori research team had already exposed the same residential-proxy botnet running on other device classes, including television set-top boxes, well before automotive head units became one of its enrollment targets. The pattern is consistent across device types: compromised hardware quietly resells its internet connection as a residential IP address, the kind that ad-fraud operations and other proxy buyers pay for precisely because it looks like ordinary consumer traffic rather than a data-center server.

What changed with this campaign, as documented around August 21 and 22, 2026, is the device class, not the business model. A botnet built from television boxes and one built from car head units both exist to sell the same thing: bandwidth and IP reputation stolen from devices their owners still believe are working only for them.

The Fix Is Auditing the Update Pipeline, Not the Showroom Floor

A supplier's firmware-update pipeline, not the car sitting on a dealership lot, is where this campaign actually lives, because JarService rode in through DoFun's own update mechanism rather than through any action the driver or dealer took. Auditing head-unit software once, at the point of sale, checks a snapshot that is already out of date the moment the first over-the-air update lands. Whoever compromises the supplier's update channel gets a persistent foothold in every vehicle downstream, silently, and re-checking the device after delivery does nothing to close that channel.

The lesson holds beyond this one campaign: any fleet or dealership that treats vehicle software the way it treats a one-time safety inspection is trusting a supply chain it has never actually verified. The fix is not a better scan of the car in the lot; it is auditing the update pipeline itself, every push, for as long as the vehicle stays connected.