Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
4 clusters · 26 sources · 7 days · First seen · Last updated
Cybersecurity risks in automotive infotainment systems
Overview
Researchers have identified a novel Android malware campaign specifically targeting automotive head units, marking the first documented case of an infection chain tailored for this device type. Discovered in June 2026, the attack targets DoFun-powered head units, which are commonly used as aftermarket accessories.
The campaign, potentially linked to the MoYu Group and the BadBox botnet, exploits the official firmware update mechanism of several models. Attackers leverage a legitimate system application called TWCore, which manages software updates and analytics, to inject a dropper known as JarService. This malicious program operates silently in the background without a user interface, making detection difficult for drivers.
Once installed, JarService can execute up to nine different commands. Its primary objectives include conducting large-scale advertising fraud, displaying unwanted advertisements, and building a proxy botnet using the infected vehicles. The malware also collects technical device data, such as screen resolution, device models, Wi-Fi network identifiers, and MAC addresses. While the malware targets connectivity and data, researchers noted there is currently no evidence that it directly controls critical driving functions like steering or braking.
Security experts, including teams from Kaspersky, have highlighted that this method is particularly concerning because it bypasses standard user precautions by using legitimate over-the-air (OTA) firmware update mechanisms. Unlike Android Auto, which mirrors phone functions, this attack affects standalone Android-based infotainment systems with their own processors and internet connectivity. Experts warn that the infection may be detectable by observing unusual system behavior, such as “significant screen lag, frequent spontaneous reboots, or excessive internet data consumption.”
Data from Upstream Security indicates that 92 percent of automotive cybersecurity incidents are conducted remotely without the need for physical access. DoFun has reportedly addressed and fixed the security vulnerability within the TWCore update function.
Entities
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 10 SOURCES] Kaspersky identified the first documented malware campaign specifically designed to target automotive infotainment systems. www.20minutos.es · www.androidsis.com · www.batista70phone.com · www.todoandroid.es · www.generation-nt.com · +5 more
- [● 9 SOURCES] The attack targets Android-based head units manufactured by DoFun. www.20minutos.es · www.androidsis.com · www.todoandroid.es · www.generation-nt.com · www.go4it.ro · +4 more
- [● 8 SOURCES] Attackers exploit a legitimate system application called TWCore to inject malicious code. www.20minutos.es · www.androidsis.com · www.todoandroid.es · www.generation-nt.com · www.go4it.ro · +3 more
- [● 8 SOURCES] The malware can execute up to nine different commands, including displaying unwanted ads and performing advertising fraud. www.20minutos.es · www.androidsis.com · www.todoandroid.es · www.mediafax.ro · www.computerworld.dk · +3 more
- [● 5 SOURCES] The malware campaign was discovered in June 2026. www.20minutos.es · www.batista70phone.com · www.go4it.ro · www.mediafax.ro · www.next-mobility.de
- [● 5 SOURCES] The malware is distributed via legitimate automatic firmware update services. www.kaspersky.com.br · www.yenimesaj.com.tr · www.quotidianomotori.com · www.haber7.com · androidportal.hu
- [● 3 SOURCES] The campaign is attributed to the MoYu threat group, which is linked to the BadBox botnet. www.generation-nt.com · www.go4it.ro · www.mediafax.ro
- [● 3 SOURCES] The manufacturer DoFun has reportedly resolved the issue. www.go4it.ro · www.mediafax.ro · www.tecnobreak.com
- [● 2 SOURCES] 92 percent of cybersecurity incidents in vehicles are carried out remotely without physical contact. www.yenimesaj.com.tr · www.haber7.com
Timeline
-
13 days ago
[TECHNOLOGY] 5 sourcesAndroid malware targets automotive infotainment systems via firmware updatesKaspersky has discovered Android malware targeting automotive infotainment systems via legitimate firmware updates to facilitate advertising fraud and create proxy botnets.
-
18 days ago
[TECHNOLOGY] 10 sourcesDoFun automotive infotainment systems targeted by new Android malwareKaspersky has discovered the first malware campaign specifically targeting Android-based car infotainment systems, using compromised DoFun updates to perform advertising fraud and data collection.
-
20 days ago
[TECHNOLOGY] 2 sourcesAutomotive technology advances introduce new safety and cybersecurity risksModern vehicle connectivity introduces new risks, including electronic door handle failures and Android-based malware that exploits over-the-air updates to target infotainment systems.
-
20 days ago
[TECHNOLOGY] 9 sourcesAndroid malware targets vehicle infotainment systems via official updatesKaspersky has uncovered a new Android malware campaign targeting vehicle infotainment systems via official firmware updates to conduct ad fraud and create proxy botnets.
Sources
ad-hoc-news.de · androidportal.hu · androidsis.com · batista70phone.com · borncity.com · computerworld.dk · cybernoz.com · engineeringchoice.com · generation-nt.com · go4it.ro · gzt.com · haber7.com · internethaber.com · it-online.co.za · kaspersky.com.br · mediafax.ro · mobilsiden.dk · next-mobility.de · que.com · quotidianomotori.com · tecnobreak.com · therecord.media · todoandroid.es · vosveteit.zoznam.sk · yenimesaj.com.tr · zdrowymagazyn.pl
This summary has been updated 4 times: see revision history