
The discovery shows that Internet-connected cars can be just as vulnerable as other smart devices and appliances. (Image for representation only)

Share Post

The discovery shows that Internet-connected cars can be just as vulnerable as other smart devices and appliances. (Image for representation only)
Security firm Kaspersky’s Threat Research team has published details of what it’s calling the world’s first documented case of malware that specifically targets car infotainment head units via their automatic update capabilities. Although it takes multiple steps for the malicious payload to carry out its attack, compromised systems can be used by the attacker to run malicious activities including advertising fraud.
The threat applies to factory-fitted as well as aftermarket Android-based head units from a Chinese manufacturer called DoFun, which has developed its own custom Android-based OS and cloud-based applications used by around 30 million cars around the world. The malware was distributed through DoFun’s over-the-air update mechanisms. According to Kaspersky, the vulnerabilities that allowed this attack were disclosed and patched before it publicly disclosed their existence.
Many car infotainment systems feature always-on Internet connections via their own cellular 5G SIMs, making them tempting targets for malicious actors. In this case, a legitimate process called TWCore, which is ordinarily used to let the manufacturer collect analytics and deliver software updates, was compromised. Attackers were able to insert their own malware into the process, and deliver them directly to affected head units no matter where they were.
The malware was designed to evade detection, and only ran in the background on infected systems, without any indication to the user that anything was out of the ordinary. This initial incursion could then be used as a backdoor through established security protocols, for attackers to deliver the actual payload. Ultimately, the malware was capable of displaying unwanted ads, transmitting unique identifying information, and even downloading and executing any additional software that the attacker might have wanted to.
Victims might never see anything suspicious, although they might notice spikes in cellular data usage or their infotainment systems becoming sluggish, as the malware consumes resources in the background.
Attackers could also have leveraged the internet connections and processing power of compromised systems as parts of a massive botnet, capable of carrying out distributed attacks on any target. This development once again highlights the risks of improperly secured Internet-connected devices.
Kaspersky has linked this malware to a group called MoYu, which in turn is affiliated with a botnet called BadBox, made up of a massive number of Android-based devices. The techniques used are similar to previously detected attacks on TV set-top boxes and other smart home appliances, which are similarly always connected to the Internet and have some local compute capabilities.
Maruti Suzuki Reveals Fuel Efficiency For CNG+AMT Variants Of Dzire, Swift And Baleno
Acko Drive Team 18 Sept, 2026, 2:26 PM IST
Mahindra Files Design Patent for Vision.SXT Cabin, Previews Production Dashboard Ahead of 2028 Launch
Ameya Naik 18 Sept, 2026, 1:15 PM IST
S Jaishankar Meets Bhutan PM Tshering Tobgay; India Hands Over 54 Made-In-India Electric Vehicles
Acko Drive Team 18 Sept, 2026, 12:23 PM IST
Mahindra XUV 3XO REVX Edge Launched Starting at ₹9.39 Lakh
Tushaar Singh Gill 18 Sept, 2026, 12:01 PM IST
Meet the Ultraviolette X-47 Skyforce: India's New Electric Police Patrol Bike
Arun Mohan Nadar 18 Sept, 2026, 11:29 AM IST
Looking for a new car?
We promise the best car deals and earliest delivery!
