Only one outlet has reported this event so far — you're reading it below, credited to its source. AIPROPX is tracking the web for more coverage; as additional outlets confirm it, this becomes a full multi-source story automatically.
By AIPROPX Editorial Desk · Published · Updated
One outlet is reporting this so far. AIPROPX is tracking it and will gather every additional source as it develops — the full multi-source comparison appears automatically once a second outlet confirms it.

Kaspersky found Android malware abusing DoFun car head units via TWCore updates
Multi‑stage attack installs loaders and reverse proxy, aiming to build a botnet of connected cars
Campaign attributed to MoYu Group; DoFun patched vulnerabilities after disclosure
We’ve seen botnets comprising cameras and DVRs, we’ve even seen botnets comprising smart fridges and digital frames, but we’ve never seen botnets comprising automobile infotainment systems . First time for everything.
Earlier this week, security researchers Kaspersky warned about finding a brand new Android malware targeting the car’s head unit. The victim seems to be a Chinese manufacturer called DoFun. Head units from this manufacturer, built on Android, are running an app for analytics and software updates called TWCore.
According to Kaspersky, the attackers abused TWCore’s update mechanisms, instructing it to download a malicious APK. This malware is then placed in the app’s cache directory and installed by the legitimate com.tw.core package.
No active campaigns
The researchers said this was a multi-stage attack. In the first stage, a tiny dropper with no user interface gets deployed. It decrypts embedded data, and extracts the information it needs for stage two. In the next stage, the loader contacts the attackers’ server and gets instructions about stage 3, which can be different things, from deploying additional malware, to running the “zhima” reverse proxy.
Despite its multifunctional nature, Kaspersky believes that the true goal of the campaign is to assimilate the cars into a botnet. Some cars come with a SIM slot and are connected to the internet 24/7. It is probably not an exaggeration to say that cars just might be the perfect devices for a malicious botnet.
Kaspersky attributed the campaign to MoYu Group, a threat actor known for building malicious botnets based on Android devices. In the past, this group was observed building the BadBox botnet out of Android smartphones, tablets, streaming devices, and other internet-connected hardware.
The researchers notified DoFun of their findings, and the vulnerability was quickly fixed: "We notified the vendor about the distribution scheme, and they subsequently reported fixing the security issues," the researchers said.
Via The Record
Indexed and credited by AIPROPX. Originating outlet: TechRadar. Open at source →
An original, deterministic readout — composed only from the computed coverage facts on this page. No interpretation, no rating; figures only.
AIPROPX has consolidated 1 report from 1 outlet into a single canonical entry on “Android car systems abused by hackers to launch new malware that pulls devices into a hidden proxy network.” Every covered outlet is based in Other.
The only timestamped report came from TechRadar (Aug 25, 2026, 13:10 UTC).
2 statements are carried by only one outlet within this set and are not echoed by the others.
Every figure above is a direct count of real published articles. AIPROPX indexes and compares the original reporting — it never rewrites, rates, or editorializes — and each publisher’s full article is always one click away.
Generated by AIPROPX from the source counts above. AIPROPX indexes and resolves coverage; the original publishers are credited and linked at origin in every report.
Coverage from 1 independent outlet across 1 region — each view opens on its own page.
AIPROPX — “Android car systems abused by hackers to launch new malware that pulls devices into a hidden proxy network” · https://www.aipropx.com/story/121644482df8f61dbf2bf0932c29cc32
Other events being covered across multiple sources right now.
How to watch the Nancy Grace Roman Space Telescope's launch
6 outletsDue to need for "absolute success," China delays critical Moon launch to 2027
5 outletsLet the team cook. It will be worth the wait' — CD Projekt Red confirms The Witcher 4 is 'targeting' a 2028 launch
5 outletsSpaceX sets rocket-reuse record on 100th Falcon 9 launch of the year (video)
1 outletsMarvel Tōkon Devs Say Botched PC Launch Will Make Regaining Player Trust ‘Extremely Challenging
1 outletsApple outlines 50 ways to make devices easier to use as we age