
The discovery shows that Internet-connected cars can be just as vulnerable as other smart devices and appliances. (Image for representation only)

Share Post

The discovery shows that Internet-connected cars can be just as vulnerable as other smart devices and appliances. (Image for representation only)
Security firm Kaspersky’s Threat Research team has published details of what it’s calling the world’s first documented case of malware that specifically targets car infotainment head units via their automatic update capabilities. Although it takes multiple steps for the malicious payload to carry out its attack, compromised systems can be used by the attacker to run malicious activities including advertising fraud.
The threat applies to factory-fitted as well as aftermarket Android-based head units from a Chinese manufacturer called DoFun, which has developed its own custom Android-based OS and cloud-based applications used by around 30 million cars around the world. The malware was distributed through DoFun’s over-the-air update mechanisms. According to Kaspersky, the vulnerabilities that allowed this attack were disclosed and patched before it publicly disclosed their existence.
Many car infotainment systems feature always-on Internet connections via their own cellular 5G SIMs, making them tempting targets for malicious actors. In this case, a legitimate process called TWCore, which is ordinarily used to let the manufacturer collect analytics and deliver software updates, was compromised. Attackers were able to insert their own malware into the process, and deliver them directly to affected head units no matter where they were.
The malware was designed to evade detection, and only ran in the background on infected systems, without any indication to the user that anything was out of the ordinary. This initial incursion could then be used as a backdoor through established security protocols, for attackers to deliver the actual payload. Ultimately, the malware was capable of displaying unwanted ads, transmitting unique identifying information, and even downloading and executing any additional software that the attacker might have wanted to.
Victims might never see anything suspicious, although they might notice spikes in cellular data usage or their infotainment systems becoming sluggish, as the malware consumes resources in the background.
Attackers could also have leveraged the internet connections and processing power of compromised systems as parts of a massive botnet, capable of carrying out distributed attacks on any target. This development once again highlights the risks of improperly secured Internet-connected devices.
Kaspersky has linked this malware to a group called MoYu, which in turn is affiliated with a botnet called BadBox, made up of a massive number of Android-based devices. The techniques used are similar to previously detected attacks on TV set-top boxes and other smart home appliances, which are similarly always connected to the Internet and have some local compute capabilities.
Mini India Introduces ‘Mod My Mini’ Official Vehicle Customisation Programme
Acko Drive Team 26 Aug, 2026, 11:13 AM IST
First Malware Targeting Android-Based Connected Car Infotainment Systems Discovered
Jamshed Avari 26 Aug, 2026, 10:30 AM IST
Maruti Suzuki Becomes First Carmaker to Dispatch Vehicles by Rail to Pollachi Terminal
Acko Drive Team 26 Aug, 2026, 9:01 AM IST
MG Hector Tomahawk PHEV and EV Launched Starting at ₹19.49 Lakh
Tushaar Singh Gill 26 Aug, 2026, 7:39 AM IST
Ather Details Extensive Testing Regime for Upcoming Konarc Electric Scooter
Tushaar Singh Gill 26 Aug, 2026, 6:50 AM IST
Looking for a new car?
We promise the best car deals and earliest delivery!
