A novel and insidious cyber threat has emerged, targeting Android-based automotive head units in a bid to spread malware and hijack update systems. Researchers at Kaspersky have uncovered a sophisticated piece of malware, dubbed JarService, which is designed to infect car infotainment modules and recruit them into a botnet for click-fraud purposes.
The malware, linked to the notorious BadBox botnet, spreads through the built-in updaters of Android-based head unit firmware, exploiting a weakness in DoFun’s software update system. This vulnerability allows malicious actors to install additional malware on infected devices, effectively turning them into proxy servers for click fraud operations. The research team discovered that an infected DoFun head unit does not pose any physical risks to drivers or passengers, as it only affects infotainment systems.
The threat is significant because it highlights the expanding scope of botnet attacks. MoYu Group, the cybercrime gang behind BadBox, has now turned its attention to vehicle systems, demonstrating a willingness to exploit new avenues for malicious activity. This development underscores the importance of cybersecurity in connected devices, which are increasingly integrated into our daily lives.
The malware’s infection chain is particularly noteworthy, as it involves abusing legitimate functionality to spread infections. Researchers found that the malware uses an application called TWCore, designed to update head units’ software, to install a multistage loader. This tactic allows malicious actors to bypass traditional security measures and evade detection.
Kaspersky researchers have notified DoFun about the security issues, and the company has reportedly fixed the weaknesses in its firmware. However, it remains unclear whether other head unit manufacturers are vulnerable to similar attacks. The discovery also raises questions about supply chain compromise, as experts suggest that a possible vulnerability in the manufacturing process may be responsible for this new threat.
The emergence of malware targeting automotive systems is a sobering reminder of the need for robust cybersecurity measures in connected devices. As our reliance on technology grows, so does the potential for malicious actors to exploit vulnerabilities and disrupt critical systems. The takeaway from this incident is clear: manufacturers must prioritize security when developing software and firmware, and users should remain vigilant about updating their devices regularly to prevent infections.
In light of these findings, it’s essential for vehicle owners to be aware of the risks associated with connected infotainment systems. While an infected DoFun head unit does not pose a physical risk, it can compromise user data and create opportunities for malicious actors to spread malware further. As we continue to integrate technology into our daily lives, we must also acknowledge the potential consequences of neglecting cybersecurity in these devices.
Source: Dark Reading — 2026-08-26