< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

4 clusters · 26 sources · 7 days · First seen · Last updated

Cybersecurity risks in automotive infotainment systems

Overview

Researchers have identified a novel Android malware campaign specifically targeting automotive head units, marking the first documented case of an infection chain tailored for this device type. Discovered in June 2026, the attack targets DoFun-powered head units, which are commonly used as aftermarket accessories.

The campaign, potentially linked to the MoYu Group and the BadBox botnet, exploits the official firmware update mechanism of several models. Attackers leverage a legitimate system application called TWCore, which manages software updates and analytics, to inject a dropper known as JarService. This malicious program operates silently in the background without a user interface, making detection difficult for drivers.

Once installed, JarService can execute up to nine different commands. Its primary objectives include conducting large-scale advertising fraud, displaying unwanted advertisements, and building a proxy botnet using the infected vehicles. The malware also collects technical device data, such as screen resolution, device models, Wi-Fi network identifiers, and MAC addresses. While the malware targets connectivity and data, researchers noted there is currently no evidence that it directly controls critical driving functions like steering or braking.

Security experts, including teams from Kaspersky, have highlighted that this method is particularly concerning because it bypasses standard user precautions by using legitimate over-the-air (OTA) firmware update mechanisms. Unlike Android Auto, which mirrors phone functions, this attack affects standalone Android-based infotainment systems with their own processors and internet connectivity. Experts warn that the infection may be detectable by observing unusual system behavior, such as “significant screen lag, frequent spontaneous reboots, or excessive internet data consumption.”

Data from Upstream Security indicates that 92 percent of automotive cybersecurity incidents are conducted remotely without the need for physical access. DoFun has reportedly addressed and fixed the security vulnerability within the TWCore update function.

Entities

Android · Kaspersky · DoFun · BADBOX · TWCore

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 13 days ago

    [TECHNOLOGY] 5 sources
    Android malware targets automotive infotainment systems via firmware updates

    Kaspersky has discovered Android malware targeting automotive infotainment systems via legitimate firmware updates to facilitate advertising fraud and create proxy botnets.

  2. 18 days ago

    [TECHNOLOGY] 10 sources
    DoFun automotive infotainment systems targeted by new Android malware

    Kaspersky has discovered the first malware campaign specifically targeting Android-based car infotainment systems, using compromised DoFun updates to perform advertising fraud and data collection.

  3. 20 days ago

    [TECHNOLOGY] 2 sources
    Automotive technology advances introduce new safety and cybersecurity risks

    Modern vehicle connectivity introduces new risks, including electronic door handle failures and Android-based malware that exploits over-the-air updates to target infotainment systems.

  4. 20 days ago

    [TECHNOLOGY] 9 sources
    Android malware targets vehicle infotainment systems via official updates

    Kaspersky has uncovered a new Android malware campaign targeting vehicle infotainment systems via official firmware updates to conduct ad fraud and create proxy botnets.

Sources

ad-hoc-news.de · androidportal.hu · androidsis.com · batista70phone.com · borncity.com · computerworld.dk · cybernoz.com · engineeringchoice.com · generation-nt.com · go4it.ro · gzt.com · haber7.com · internethaber.com · it-online.co.za · kaspersky.com.br · mediafax.ro · mobilsiden.dk · next-mobility.de · que.com · quotidianomotori.com · tecnobreak.com · therecord.media · todoandroid.es · vosveteit.zoznam.sk · yenimesaj.com.tr · zdrowymagazyn.pl

This summary has been updated 4 times: see revision history