started · updated
DoFun automotive infotainment systems targeted by new Android malware
Kaspersky researchers have identified the first documented malware campaign specifically designed to target Android-based automotive infotainment systems. The malware, identified as JarService, targets head units manufactured by DoFun, which are commonly used in the automotive accessory market.
The infection occurs through a compromised software update mechanism. Attackers exploited a legitimate system application called TWCore, which is responsible for managing updates and collecting analytics, to inject the malicious code. Once installed, JarService operates silently in the background without a user interface, allowing it to perform up to nine different commands.
Key malicious activities include displaying unwanted advertisements, executing large-scale advertising fraud, and downloading additional malicious modules. The malware also collects technical data from the vehicle, such as the device model, screen resolution, MAC address, and connected Wi-Fi network information. The campaign is attributed to the MoYu threat group, which is linked to the BadBox botnet.
While the malware can access internet connectivity via SIM card slots in many units, researchers noted there is currently no evidence that it can directly control critical vehicle functions like steering or braking. DoFun has reportedly been notified and has resolved the vulnerabilities used in the attack.
Entities
Android · BADBOX · DoFun · JarService · Kaspersky · MoYu · TWCore
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 6 SOURCES] The injected malicious program is named JarService. www.20minutos.es · www.androidsis.com · www.todoandroid.es · www.generation-nt.com · www.mediafax.ro · +1 more
- [● 3 SOURCES] The manufacturer DoFun has reportedly resolved the issue. www.go4it.ro · www.mediafax.ro · www.tecnobreak.com
- [● 8 SOURCES] The malware can execute up to nine different commands, including displaying unwanted ads and performing advertising fraud. www.20minutos.es · www.androidsis.com · www.todoandroid.es · www.mediafax.ro · www.computerworld.dk · +3 more
- [● 3 SOURCES] The campaign is attributed to the MoYu threat group, which is linked to the BadBox botnet. www.generation-nt.com · www.go4it.ro · www.mediafax.ro
- [● 8 SOURCES] Attackers exploit a legitimate system application called TWCore to inject malicious code. www.20minutos.es · www.androidsis.com · www.todoandroid.es · www.generation-nt.com · www.go4it.ro · +3 more
- [● 10 SOURCES] Kaspersky identified the first documented malware campaign specifically designed to target automotive infotainment systems. www.20minutos.es · www.androidsis.com · www.batista70phone.com · www.todoandroid.es · www.generation-nt.com · +5 more
- [● 9 SOURCES] The attack targets Android-based head units manufactured by DoFun. www.20minutos.es · www.androidsis.com · www.todoandroid.es · www.generation-nt.com · www.go4it.ro · +4 more
- [● 5 SOURCES] The malware campaign was discovered in June 2026. www.20minutos.es · www.batista70phone.com · www.go4it.ro · www.mediafax.ro · www.next-mobility.de