In June 2026, Kaspersky uncovered a novel Android malware targeting vehicle Head Units – systems combining multimedia and, in some cases, car control functions. Taking the form of a stealthy multi-stage downloader, this campaign marks the first documented case of malware infecting a car’s head unit through an infection chain explicitly tailored for these vehicle systems. The goal is to deploy multi-stage malware that would enable carrying out ad fraud and other malicious activities. Kaspersky researchers believe this activity may be attributed to the MoYu Group, a threat actor closely tied to the infamous BadBox botnet.