< Back to all clusters
[TECHNOLOGY] · China, Denmark, Germany, Spain, France · 10 sources

started · updated

DoFun automotive infotainment systems targeted by new Android malware

Kaspersky researchers have identified the first documented malware campaign specifically designed to target Android-based automotive infotainment systems. The malware, identified as JarService, targets head units manufactured by DoFun, which are commonly used in the automotive accessory market.

The infection occurs through a compromised software update mechanism. Attackers exploited a legitimate system application called TWCore, which is responsible for managing updates and collecting analytics, to inject the malicious code. Once installed, JarService operates silently in the background without a user interface, allowing it to perform up to nine different commands.

Key malicious activities include displaying unwanted advertisements, executing large-scale advertising fraud, and downloading additional malicious modules. The malware also collects technical data from the vehicle, such as the device model, screen resolution, MAC address, and connected Wi-Fi network information. The campaign is attributed to the MoYu threat group, which is linked to the BadBox botnet.

While the malware can access internet connectivity via SIM card slots in many units, researchers noted there is currently no evidence that it can directly control critical vehicle functions like steering or braking. DoFun has reportedly been notified and has resolved the vulnerabilities used in the attack.

Entities

Android · BADBOX · DoFun · JarService · Kaspersky · MoYu · TWCore

Claims

What the coverage asserts, and how many sources carry each claim.