Security Company Says Hackers Are Turning Car Infotainment Systems Into Botnets Modern infotainment systems increasingly resemble connected computers, and that also means they can attract the same kinds of threats. Security researchers have now documented malware being distributed to certain Android-based car head units in the wild. According to Kaspersky, the malware was discovered in June 2026 and represents the first documented case of malicious software being delivered to automotive head units through an automatic firmware-update service. Unlike many previous automotive cybersecurity stories, this was not simply a controlled security experiment. The campaign targets infotainment systems running software developed by Chinese company DoFun, which Kaspersky says provides firmware, applications, and cloud services for Android-based head units. The company serves more than 30 million vehicle owners worldwide, although Kaspersky did not suggest that every one of those devices was affected. The malware is primarily designed to exploit the infotainment system's computing power and internet connection. Researchers linked the campaign to ad fraud and a proxy botnet, effectively turning compromised car head units into remotely controlled internet-connected devices. The Malware Arrived Through A Legitimate Update App Kaspersky says attackers exploited TWCore, a legitimate system application responsible for delivering software to DoFun-based head units. Under normal circumstances, the app connects to the developer's cloud infrastructure to download updates or install software. Attackers used that mechanism to install a Trojan dropper called JarService without requiring any action from the driver. JarService contains encrypted code that launches another stage of the infection and connects with the attackers' command-and-control infrastructure. The malware can then retrieve and execute additional payloads. One of those is a so-called clicker, which can generate fraudulent advertising activity by opening web pages and making HTTP requests. Infected Cars Can Become Part Of A Botnet The malware also installs a component Kaspersky identifies
Security Company Says Hackers Are Turning <b>Car</b> Infotainment Systems Into Botnets
Read the original article
autos.yahoo.com →