AndroidPure
  • Leaks
  • News
  • Reviews
  • Updates
  • How to
No Result
View All Result
  • Leaks
  • News
  • Reviews
  • Updates
  • How to
No Result
View All Result
AndroidPure
No Result
View All Result

Kaspersky Finds the First Malware Built for Android Car Head Units

Androidpure Staff by Androidpure Staff
August 31, 2026
in News

Kaspersky says it has documented the first malware campaign built specifically for Android car head units — the touchscreen systems that handle music, navigation and, on some vehicles, parts of the car’s own controls. The findings were published on 21 August, and the awkward part for anyone driving with one of these screens in the dashboard is that neither of Kaspersky’s two write-ups names a single car brand or head unit model. The infected devices are described only as “multiple models” running firmware from a supplier called DoFun, so a reader currently has no reliable way to check whether the box in their dashboard is one of them.

Android mascot in a car driver's seat illustrating Android head unit malware found by Kaspersky
Image: Kaspersky/Securelist

How the Android head unit malware got in

The entry point was not a dodgy APK a driver sideloaded. It was the update system the head unit already trusts. DoFun firmware ships a legitimate system app called TWCore, which collects analytics and installs software updates pushed from the manufacturer’s side over an MQTT message broker. Kaspersky’s researchers found that TWCore’s update instructions carry a flag that allows it to install apps that were never on the device to begin with — and that attackers used exactly that channel to push a previously unknown dropper, JarService, straight onto the units.

From there it runs in three stages. JarService pulls down a loader that reports device details back to a command server; the loader then fetches a third component that can serve ads, commit ad fraud and download further modules. Kaspersky counted nine distinct commands available to the operators, and says the data flowing back included display resolution, device model, the connected Wi-Fi network identifier and the device’s MAC address. The payload actually being deployed at the time of the report was a reverse proxy module named zhima — meaning the real business here is renting out the car’s internet connection as a residential proxy, not stealing anything from the car itself.

Kaspersky attributes the campaign to the MoYu Group, an actor it links to the BadBox botnet already known for shipping compromised Android TV boxes. The connection was drawn partly from the operators’ own admin panel, which Securelist found sharing sign-in URL patterns and legal-document links with two residential proxy vendors, PXYEDGE and ProxyForU.

“This malware has become the very first malicious application specifically targeting car head units through an infection chain explicitly tailored for these vehicle systems,” said Dmitry Kalinin, security researcher at Kaspersky, in the company’s press release.

“Fixed” by the vendor is not the same as fixed in your car

Kaspersky notified DoFun, and says that according to DoFun the issue has been fixed. That sentence is doing a lot of work. A head unit is not a phone with a monthly security patch: factory-fitted units are updated at the pace of the carmaker’s service schedule, and aftermarket units bought online are frequently abandoned by their sellers within a year or two. A patch existing at the supplier and a patch reaching the screen in a specific car are two entirely different claims, and only the first one has been demonstrated here.

The wider point is one Android owners have run into before with cheap set-top boxes: when a device’s own update channel is the attack surface, none of the usual advice applies. The user did nothing wrong, installed nothing, and would see nothing — the malware runs with no interface at all.

What head unit owners can do now

  • Install pending firmware updates from the head unit’s own settings or from the manufacturer’s site, since the fix DoFun reports can only reach you that way.
  • Check whether the unit has a SIM slot in use. Kaspersky notes head units often carry their own SIM and permanent connectivity, which is precisely what makes them worth hijacking as proxies. If you never use the built-in data connection, there is no reason to leave it active.
  • Watch for pop-up ads on the dashboard screen, which is the one symptom of this family a driver might actually notice — the same ad-fraud behaviour that shows up as invasive ads on phones.
  • Be sceptical of no-name aftermarket units. A cheap Android head unit from an unknown seller carries the same update-channel risk as a cheap Android TV box, with no meaningful support commitment attached.

The gap that remains is the one Kaspersky’s report does not close: without a list of affected models, the practical advice stops at “update everything and hope your supplier shipped it.” For a device class that sits on a permanent internet connection inside a car, that is not a comfortable place to leave things.

Sources: Securelist, Kaspersky

Tags: Android Autoandroid securitykasperskyMalware
TweetShareSendShare
Previous Post

Google Maps Now Shows Three Different Names for Lake Ontario

Next Post

Apple Watch Series 12 Tipped for a Ceramic Case and All-Day Heart Rate

Androidpure Staff

Androidpure Staff

Androidpure Staff delivers the latest from the Android world — phone launches, software updates, and practical how-to guides — without the press-release fluff. We focus on what genuinely matters to readers, in India and around the globe.

Follow Us

  • 914 Followers

Popular

  • Google Play logo, illustrating Google's settlement of the UK app developer class action over Play Store commission

    Google Will Pay £260m to Settle UK App Developers’ Play Store Claim

    Share
    Share Tweet
  • Android 17’s Motion Assist Reaches Pixels With a Key Overlay Fix

    Share
    Share Tweet
  • Nothing OS 5.0: Which Phones Get Android 17, and When

    Share
    Share Tweet
  • Nothing OS 5.0 Open Beta Is Live on Phone (3): How to Join

    Share
    Share Tweet
  • iQOO Neo 9 Pro launched in India: Snapdragon 8 Gen 2, Price

    Share
    Share Tweet
  • Galaxy S25 Ultra May Get the S26 Ultra’s Virtual Reflector in One UI 9

    Share
    Share Tweet
  • WhatsApp’s Scam Alert Toggle Starts Appearing for Android Beta Testers

    Share
    Share Tweet

Latest

Google Search AI branding, illustrating AI Overviews expanding into AI Mode by default

Google Now Expands AI Overviews Into Full AI Mode Answers by Default

August 31, 2026
Apple Watch Series 11 in five aluminium finishes with Nike bands, the current model ahead of the Apple Watch Series 12

Apple Watch Series 12 Tipped for a Ceramic Case and All-Day Heart Rate

August 31, 2026
Android mascot in a car driver's seat illustrating Android head unit malware found by Kaspersky

Kaspersky Finds the First Malware Built for Android Car Head Units

August 31, 2026
Google Maps app branding used with Google's announcement of the Lake Ontario and Lake America name change

Google Maps Now Shows Three Different Names for Lake Ontario

August 30, 2026
Google Pixel 11 rear camera bar shown in lilac on Google's official product page

GrapheneOS Warns Against Buying the Pixel 11 After Its Port Stalled

August 30, 2026
WhatsApp app icon illustrating the Scam Alert toggle reaching Android beta testers

WhatsApp’s Scam Alert Toggle Starts Appearing for Android Beta Testers

August 30, 2026
Android robot logo, representing stock Android staying in scope of California's age verification law

California Moves to Exempt Open-Source Android From Its Age-Check Law

August 30, 2026
AndroidPure

© 2026 AndroidPure - NonStop Android.

Navigate Site

  • Privacy
  • About Us
  • Tip Us
  • Contact Us

Follow Us

No Result
View All Result
  • Leaks
  • News
  • Reviews
  • Updates
  • How to

© 2026 AndroidPure - NonStop Android.