First Documented Infection Chain

Kaspersky Discovers Car Head Unit Malware

  • First documented malware campaign targeting Android car head units
  • Attackers abused a legitimate software update mechanism
  • JarService enables ad fraud and device data collection

Kaspersky Discovers Car Head Unit Malware
Sep 27, 2026 15:09

Global cybersecurity company Kaspersky has discovered a new malware campaign targeting Android-based vehicle head units. According to the company’s research, this is the first documented case of an infection chain specifically designed to spread malware through car head units. The malware was delivered through compromised firmware update mechanisms used by multiple Android-based head units powered by DoFun.

The attack began by abusing the legitimate TWCore system app. The app normally manages device analytics and software updates. Attackers used this trusted channel to distribute JarService, a stealthy multi-stage malware downloader.

JarService was installed as a regular user application but had no visible interface. This allowed it to operate silently in the background without the user’s knowledge.

According to Kaspersky researchers, JarService contains nine commands. These commands allow attackers to display unwanted advertisements, conduct ad fraud and download additional malicious modules. The malware can also collect information such as the device model, display resolution, Wi-Fi network identifier and MAC address.

Kaspersky researchers linked the campaign to the MoYu Group, a threat actor associated with the BadBox botnet. BadBox is a large network of compromised Android devices that has been used for ad fraud, data theft and proxy traffic.

After identifying the campaign, Kaspersky notified DoFun. The company subsequently fixed the software distribution mechanism that had been abused to deliver the malware.

Dmitry Kalinin, security researcher at Kaspersky, said that despite ongoing efforts by cybersecurity experts and law enforcement agencies to shut down the BadBox botnet, groups associated with it continue to spread malware to devices worldwide.

He said malware delivery methods are becoming increasingly diverse. They range from pre-installed backdoors and compromised IPTV applications to the legitimate software update functionality of system applications.

Kalinin also said cybercriminals are actively targeting new platforms. He noted that the discovery of a malware infection chain specifically designed for car head units marks the first such case identified by Kaspersky.

According to him, the development highlights the need for strong malware protection and cybersecurity measures for modern automotive digital systems.

//DBTech/RIP/SME/MIS//