Android Malware Hijacks Update System for Car Head Units

Android Malware Hijacks Update System for Car Head Units, Highlighting Wider Botnet Threat

In a disturbing escalation of cyber threats, researchers at Kaspersky have discovered Android malware targeting car head units, the hardware modules on dashboards that control vehicle communication, entertainment, and information systems. This is the first documented case of its kind, where malicious software has been found to infect these devices through their built-in update systems.

The malware, dubbed JarService, was identified in June as part of an unusual Android threat. Initially thought to be a typical head unit app, further analysis revealed it to be a multistage malware downloader designed to infect head units and spread by abusing legitimate functionality. Specifically, the malware exploits a weakness in DoFun’s firmware update system, using an application called TWCore to download additional malware.

The research team at Kaspersky has tied this infection chain to a known cybercrime group responsible for the notorious BadBox botnet, whose ultimate goal is to create a proxy botnet for click-fraud purposes. This development highlights that threat actors are increasingly targeting all manner of devices and systems in their quest for financial gain.

Head units, although connected to the internet via SIM card slots, typically hold no valuable data for attackers. However, by infecting these devices, hackers can recruit them into a botnet, much like attacks on IoT devices. In this case, while an infected DoFun head unit does not pose physical risks to drivers or passengers, as it is purely an infotainment system, the malware can download additional malicious code.

The discovery raises questions about the security of vehicle systems and whether other manufacturers’ built-in update systems may be vulnerable to similar attacks. Fortunately, Kaspersky researchers notified DoFun about the issue, and the company has since addressed the weaknesses in their firmware.

This incident serves as a reminder that botnets are becoming increasingly sophisticated and adaptable, targeting new areas such as vehicle systems. As Lindsay Kaye, vice president of threat intelligence at Human Security, notes, “The fact that we’re seeing supply chain compromise in this case is particularly concerning.” The takeaway for consumers is to remain vigilant about the security of their connected devices and systems, and to be aware of potential vulnerabilities in the update process.

As we continue to connect more aspects of our lives to the internet, it’s essential to prioritize cybersecurity and address emerging threats before they escalate. By doing so, we can mitigate the risks posed by botnets and ensure a safer digital environment for all.


Source: Dark Reading — 2026-08-26