< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

Android malware targets automotive infotainment systems via firmware updates

Kaspersky researchers have identified a new type of Android malware specifically targeting automotive multimedia head units. In a first-of-its-kind documented case, the malware is distributed through legitimate automatic firmware update mechanisms rather than through user error or malicious downloads.

The attack targets DoFun brand head units, exploiting the TWCore update application to deploy a loader known as JarService. Once installed, the malware aims to facilitate advertising fraud and build a proxy botnet using the infected vehicles.

Unlike Android Auto, which mirrors phone functions, this attack affects standalone Android-based infotainment systems with their own processors and internet connectivity. Experts warn that infected vehicles may exhibit symptoms such as system slowdowns, frequent unexpected restarts, and excessive data consumption. While DoFun has reportedly corrected the flaw, the full extent of the infection remains unknown.

Entities

Android · BADBOX · DoFun · Google · Kaspersky · Upstream Security

Claims

What the coverage asserts, and how many sources carry each claim.