Malware in car infotainment systems: how infection occurs | Kaspersky official blog
Description
In June 2026, Kaspersky discovered malware targeting Android-based car infotainment systems (head units) developed by the Chinese company DoFun. The malware is delivered via the legitimate TWCore system app responsible for firmware updates, which attackers exploit to install a Trojan dropper called JarService without user interaction. JarService decrypts and launches a downloader that connects to a command-and-control server to fetch and execute additional payloads, including a clicker for ad fraud and a module that adds the device to a botnet used as a residential proxy service. The malware consumes system resources, potentially slowing the infotainment system and degrading internet performance. The infection is linked to the MoYu Group threat actor and the BADBOX malicious platform. The developer was informed and addressed the security issues.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This malware campaign targets Android-based automotive infotainment systems specifically using DoFun's software, affecting over 30 million vehicles worldwide. Attackers exploit the TWCore update mechanism to silently install JarService, a Trojan dropper without a user interface. JarService decrypts and executes a downloader that communicates with a C2 server to retrieve further payloads, including a clicker for ad fraud and a botnet module named zhima. The infected head units become part of a proxy botnet infrastructure linked to the MoYu Group and the BADBOX platform, enabling attackers to route malicious traffic through these devices. The malware impacts system performance and network speed and can receive commands to download and execute additional malicious code. Kaspersky notified the developer, who subsequently addressed the security flaws.
Potential Impact
The malware enables attackers to incorporate infected car infotainment systems into a botnet used for ad fraud and proxy services, potentially degrading the performance and stability of the head unit and reducing internet connection speeds. The infection vector requires no user interaction, increasing the risk of widespread compromise. The ability to download and execute additional malicious code means the impact could evolve depending on attacker intent. The compromised devices provide attackers with proxy infrastructure that can be monetized and used for further malicious activities.
Defensive Guidance
The developer of the affected infotainment systems was informed of the malware distribution method and has addressed the security issues. Users should ensure their head units receive official updates from the manufacturer or authorized sources. Since the malware exploits the legitimate update mechanism, verifying update authenticity and integrity is critical. No additional user action is required if the device has been updated with the vendor's fixes.
Technical Details
- Classification
- {"confidence":0.65,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.kaspersky.com/blog/car-botnet-malware-for-head-units-with-android/56296/","fetched":true,"fetchedAt":"2026-08-21T14:36:14.817Z","wordCount":1646}
Threat ID: 6a88625eacd9273b4942bc82
Added to database: 08/21/2026, 14:36:14 UTC
Last enriched: 09/11/2026, 02:34:15 UTC
Last updated: 10/04/2026, 00:17:20 UTC
Views: 132
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.