started · updated
Android malware targets automotive infotainment systems via firmware updates
Kaspersky researchers have identified a new type of Android malware specifically targeting automotive multimedia head units. In a first-of-its-kind documented case, the malware is distributed through legitimate automatic firmware update mechanisms rather than through user error or malicious downloads.
The attack targets DoFun brand head units, exploiting the TWCore update application to deploy a loader known as JarService. Once installed, the malware aims to facilitate advertising fraud and build a proxy botnet using the infected vehicles.
Unlike Android Auto, which mirrors phone functions, this attack affects standalone Android-based infotainment systems with their own processors and internet connectivity. Experts warn that infected vehicles may exhibit symptoms such as system slowdowns, frequent unexpected restarts, and excessive data consumption. While DoFun has reportedly corrected the flaw, the full extent of the infection remains unknown.
Entities
Android · BADBOX · DoFun · Google · Kaspersky · Upstream Security
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] The attack targets DoFun brand head units. www.quotidianomotori.com
- [● 5 SOURCES] The malware is distributed via legitimate automatic firmware update services. www.kaspersky.com.br · www.yenimesaj.com.tr · www.quotidianomotori.com · www.haber7.com · androidportal.hu
- [● 2 SOURCES] 92 percent of cybersecurity incidents in vehicles are carried out remotely without physical contact. www.yenimesaj.com.tr · www.haber7.com
- [● 5 SOURCES] Kaspersky researchers identified the first Android malware specifically designed for automotive multimedia systems (head units). www.kaspersky.com.br · www.yenimesaj.com.tr · www.quotidianomotori.com · www.haber7.com · androidportal.hu
- [● 3 SOURCES] The malware aims to commit advertising fraud and create a proxy botnet. www.kaspersky.com.br · androidportal.hu · www.quotidianomotori.com
- [● 2 SOURCES] Attackers exploit the TWCore update application to send the JarService loader. www.yenimesaj.com.tr · www.haber7.com