Chinanews
TechIT之家Sun, 30 Aug 2026 12:10:51 GMT

Kaspersky Discovers Car Infotainment Malware; Android Systems by DoFun at Risk of Hijacking

Kaspersky Discovers Car Infotainment Malware; Android Systems by DoFun at Risk of Hijacking
车载恶意软件网络安全安卓车机卡巴斯基

IT Home, August 30 — As cars become smarter, they are increasingly exposed to cyberattacks, methods that previously targeted computers and mobile phones.

Now, some modern cars equipped with Android systems are facing such risks. According to Autoevolution, security researchers at Kaspersky have discovered a new malware capable of infiltrating automotive infotainment systems, allowing attackers to take control of the head unit and further deploy other malicious programs.

However, before worrying about whether their Android head units are at risk, car owners first need to check the vehicle manufacturer. Kaspersky stated that currently, only Android head units running software developed by a Chinese company named DoFun are affected. DoFun claims its software is already running in over 30 million vehicles globally, and these vehicles are not exclusively distributed in China.

Therefore, theoretically, all these vehicles could be exposed to this malware attack.

As learned by IT Home, to infiltrate Android head units running DoFun software, attackers first need to exploit a system service installed by the automaker. This service was originally intended specifically by the automaker to push software updates and install new applications.

Hackers found a way to exploit this service, named TWCore, to install a malicious file called JarService. Once JarService is installed in the head unit, attackers can further perform various operations on the system.

Kaspersky explained: "The JarService code contains the next-stage payload in encrypted form, along with information about its version and entry point. JarService's task is to decrypt this data and launch the next stage of infection, which is a malicious downloader."

This downloader connects to a command-and-control server. Attackers can use this server to obtain more information about the infected device and the installed malware, while also utilizing it to control the compromised system.

For example, attackers can acquire information such as the head unit model, screen resolution, the wireless network used for internet connection, and MAC address. They can also send commands to the infected head unit and even remotely open web pages.

Security researchers stated: "But most importantly, it can download and execute other malicious code on the infotainment system of the compromised car."

For instance, attackers can incorporate the head unit into a botnet and use it as a proxy server, forwarding network traffic through the vehicle's device. They can also use the infected head unit to launch further cyberattacks.

These additional features are provided by another payload named zhima. Kaspersky discovered that the hacker group behind this may be the MoYu Group.

The security firm noted: "During the investigation of the botnet infrastructure, our experts discovered an association between the MoYu Group and the PXYEDGE and ProxyForU services, both of which provide residential proxy services."

Clearly, once a car's infotainment system is compromised and incorporated into a botnet, the head unit's operational performance may be noticeably affected, especially when system resources are used to execute various malicious activities.

One of the first phenomena to appear is a noticeable slowdown in various operations on the head unit's screen. For example, the loading time may significantly increase when launching apps like Google Maps, Waze, Spotify, or YouTube Music. This is because the head unit's system resources are being consumed in the background by malicious tasks executed by the attackers.

The second potential issue is a noticeable drop in internet speed. When using online apps like YouTube Music or Spotify, users may find their network connection speed slowing down. If the time required for these apps to load or download songs increases significantly, the head unit may have become part of a botnet and is being used as a proxy server for a certain network user.

However, most concerningly, once attackers deploy the necessary malware on the infected head unit, they can essentially do whatever they want with the device, as they have already gained complete control over it.

Kaspersky explained: "The malware's capabilities are not limited to providing proxy functionality. It can receive commands from attackers and download and execute other malicious code. Therefore, the consequences of the infection will vary, depending on which payload the botnet operator decides to install on the device.

For Android head unit users, there are several key points to note.

First, only the infotainment systems developed by this Chinese company are affected; not all Android head units are subject to this risk.

Second, these attacks can only be successful when the head unit is connected to the internet. For example, when the owner connects the head unit to the internet via an in-car data plan or a mobile hotspot. If the owner only uses the head unit offline, such as navigating with offline maps, attackers cannot infiltrate the system in this way.

Currently, the manufacturer has released a patch to fix the vulnerability exploited by attackers through the head unit's update service. Therefore, if your car is equipped with this Chinese company's infotainment system, it is best to install the latest software version immediately. Owners can connect the head unit to the internet, check for available software updates, and install the latest version to ensure the vulnerability has been fixed.

If the head unit does not offer software updates, the vehicle manufacturer should be contacted to inquire about how to install the patched firmware version for the vehicle.