[REVISION HISTORY]
Cybersecurity risks in automotive infotainment systems
Updated 4 times since CLSTR started tracking revisions of this situation.
What changed
2026-08-31 08:53 UTC → 2026-08-31 09:08 UTC ·
added
removed
Researchers have identified a novel Android malware campaign specifically targeting automotive head units, marking the first documented case of an infection chain tailored for this device type. Discovered in June 2026, the attack targets DoFun-powered head units, which are commonly used as aftermarket accessories. The campaign, potentially linked to the MoYu Group and the BadBox botnet, exploits the official firmware update mechanism of several models. Attackers leverage a legitimate system application called TWCore, which manages software updates and analytics, to inject a dropper known as JarService. This malicious program operates silently in the background without a user interface, making detection difficult for drivers. Once installed, JarService can execute up to nine different commands. Its primary objectives include conducting large-scale advertising fraud, displaying unwanted advertisements, and downloading additional malicious modules. building a proxy botnet using the infected vehicles. The malware also collects technical device data, such as screen resolution, device models, Wi-Fi network identifiers, and MAC addresses. While the malware targets connectivity and data, researchers noted there is currently no evidence that it directly controls critical driving functions like steering or braking. Security experts, including teams from Kaspersky, have highlighted that this method is particularly concerning because it bypasses standard user precautions by using legitimate over-the-air (OTA) firmware update mechanisms. Unlike Android Auto, which mirrors phone functions, this attack affects standalone Android-based infotainment systems with their own processors and internet connectivity. Experts warn that the infection may be detectable by observing unusual system behavior, such as “significant screen lag, frequent spontaneous reboots, or excessive internet data consumption.” Data from Upstream Security indicates that 92 percent of automotive cybersecurity incidents are conducted remotely without the need for physical access. DoFun has reportedly addressed and fixed the security vulnerability within the TWCore update function.
Versions
- 2026-08-31 09:08 UTC Cybersecurity risks in automotive infotainment systems
- 2026-08-31 08:53 UTC Cybersecurity risks in automotive infotainment systems
- 2026-08-31 08:46 UTC Cybersecurity risks in automotive infotainment systems
- 2026-08-26 07:46 UTC Cybersecurity risks in automotive infotainment systems
- 2026-08-24 12:43 UTC Cybersecurity risks in automotive infotainment systems
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.