# Cybersecurity risks in automotive infotainment systems

> Live situation record from CLSTR: https://clstr.news/situations/cybersecurity-risks-in-automotive-infotainment-systems
> Updated: 2026-08-29T12:40:59.000Z. Sources: 26. Developments: 4.

Researchers have identified a novel Android malware campaign specifically targeting automotive head units, marking the first documented case of an infection chain tailored for this device type. Discovered in June 2026, the attack targets DoFun-powered head units, which are commonly used as aftermarket accessories.

The campaign, potentially linked to the MoYu Group and the BadBox botnet, exploits the official firmware update mechanism of several models. Attackers leverage a legitimate system application called TWCore, which manages software updates and analytics, to inject a dropper known as JarService. This malicious program operates silently in the background without a user interface, making detection difficult for drivers.

Once installed, JarService can execute up to nine different commands. Its primary objectives include conducting large-scale advertising fraud, displaying unwanted advertisements, and building a proxy botnet using the infected vehicles. The malware also collects technical device data, such as screen resolution, device models, Wi-Fi network identifiers, and MAC addresses. While the malware targets connectivity and data, researchers noted there is currently no evidence that it directly controls critical driving functions like steering or braking.

Security experts, including teams from Kaspersky, have highlighted that this method is particularly concerning because it bypasses standard user precautions by using legitimate over-the-air (OTA) firmware update mechanisms. Unlike Android Auto, which mirrors phone functions, this attack affects standalone Android-based infotainment systems with their own processors and internet connectivity. Experts warn that the infection may be detectable by observing unusual system behavior, such as “significant screen lag, frequent spontaneous reboots, or excessive internet data consumption.”

Data from Upstream Security indicates that 92 percent of automotive cybersecurity incidents are conducted remotely without the need for physical access. DoFun has reportedly addressed and fixed the security vulnerability within the TWCore update function.

## Claims

- Kaspersky identified the first documented malware campaign specifically designed to target automotive infotainment systems. (corroborated by 10 sources)
- The attack targets Android-based head units manufactured by DoFun. (corroborated by 9 sources)
- Attackers exploit a legitimate system application called TWCore to inject malicious code. (corroborated by 8 sources)
- The malware can execute up to nine different commands, including displaying unwanted ads and performing advertising fraud. (corroborated by 8 sources)
- The malware campaign was discovered in June 2026. (corroborated by 5 sources)
- The malware is distributed via legitimate automatic firmware update services. (corroborated by 5 sources)
- The campaign is attributed to the MoYu threat group, which is linked to the BadBox botnet. (corroborated by 3 sources)
- The manufacturer DoFun has reportedly resolved the issue. (corroborated by 3 sources)
- 92 percent of cybersecurity incidents in vehicles are carried out remotely without physical contact. (corroborated by 2 sources)

## Timeline

### 2026-08-29: Android malware targets automotive infotainment systems via firmware updates

Kaspersky has discovered Android malware targeting automotive infotainment systems via legitimate firmware updates to facilitate advertising fraud and create proxy botnets.

5 sources. https://clstr.news/cluster/android-automotive-infotainment-systems-targeted-by-firmware-malware

### 2026-08-24: DoFun automotive infotainment systems targeted by new Android malware

Kaspersky has discovered the first malware campaign specifically targeting Android-based car infotainment systems, using compromised DoFun updates to perform advertising fraud and data collection.

10 sources. https://clstr.news/cluster/dofun-automotive-multimedia-screens-targeted-by-new-jarservice-malware

### 2026-08-23: Automotive technology advances introduce new safety and cybersecurity risks

Modern vehicle connectivity introduces new risks, including electronic door handle failures and Android-based malware that exploits over-the-air updates to target infotainment systems.

2 sources. https://clstr.news/cluster/automotive-technology-advances-introduce-new-safety-and-cybersecurity-risks

### 2026-08-22: Android malware targets vehicle infotainment systems via official updates

Kaspersky has uncovered a new Android malware campaign targeting vehicle infotainment systems via official firmware updates to conduct ad fraud and create proxy botnets.

9 sources. https://clstr.news/cluster/malware-targets-android-based-vehicle-infotainment-systems

---
Cite as: Cybersecurity risks in automotive infotainment systems. CLSTR, https://clstr.news/situations/cybersecurity-risks-in-automotive-infotainment-systems
