ok.com
Browse
Log in / Register

First malware targeting vehicle infotainment systems discovered — Kaspersky

OKer_t3l9mvs
08/22/2026, 02:42:49 AM
vehicle malware

Kaspersky researchers have uncovered the first documented malware campaign specifically targeting Android-based vehicle infotainment systems, marking a new frontier in automotive cyber threats. The attack chain exploits legitimate update mechanisms to deploy hidden ad fraud code, with ties to the notorious MoYu cybercrime group and the BadBox botnet. This development, reported on April 24, 2025, underscores the growing vulnerability of connected car systems as they become more integrated with mobile operating systems.

Unlike traditional car hacks that focus on engine control units or door locks, this campaign zeroes in on the multimedia head unit — the touchscreen console that combines entertainment, navigation, and sometimes vehicle settings. According to Kaspersky’s threat intelligence team, the malware was delivered via a multi-stage downloader that operates stealthily in the background. The attackers compromised the TWCore system application, a legitimate component used by several Chinese Android screen providers, including DoFun, to collect analytics and manage firmware updates. By manipulating this channel, the hackers injected a hidden installer named JarService, which runs without any user interface, making it virtually invisible to drivers.

The primary goal of the campaign is massive advertising fraud. Once installed, the malware can execute nine different commands, ranging from displaying intrusive pop-up ads to downloading additional malicious modules. The attackers also collect technical data about the vehicle, including screen resolution, model, connected Wi-Fi network, and MAC address. While these infotainment systems rarely store sensitive personal data, they often have a SIM card slot and always-on internet connectivity for map updates and real-time traffic, making them an attractive entry point for cybercriminals seeking a stable, unattended foothold.

Kaspersky’s analysis links the campaign to the MoYu Group, a threat actor previously associated with the BadBox botnet — a massive network of infected Android devices used for traffic diversion and data theft. The infrastructure powering this attack shares code and command-and-control panels with illegal relay services tied to BadBox, suggesting a coordinated effort to monetize compromised vehicle screens. DoFun, the device manufacturer named in the report, has confirmed that it has patched the vulnerability following Kaspersky’s disclosure, though the company did not specify how many devices were affected.

This discovery highlights a critical blind spot in automotive cybersecurity. While automakers and suppliers invest heavily in securing vehicle controls and telematics, third-party aftermarket screens and infotainment systems often run less scrutinized Android builds. “The attack exploits the very feature that makes infotainment systems convenient — their ability to receive updates,” said a Kaspersky researcher. “Manufacturers must adopt the same security rigor for these systems as they do for safety-critical components.” The researchers recommend that car owners only install official updates from trusted sources, disable unnecessary developer options, and consider using a dedicated mobile security app on their vehicle’s Android system if available.

The FBI and National Highway Traffic Safety Administration (NHTSA) have not yet issued a public advisory, but industry experts expect increased scrutiny on aftermarket Android units. For now, drivers with DoFun-branded screens or similar generic Android head units should check for firmware updates and contact their vendor for security patches. As connected cars become more common, this incident serves as a wake-up call: your car’s entertainment system may be the weak link in your digital life.

Cookie
Cookie Settings
Our Apps
Download
Download on the
APP Store
Download
Get it on
Google Play
© 2025 Servanan International Pte. Ltd.