← Back to blog

Android Car Malware Exploits Firmware Updaters

New malware targets Android vehicle head units via built-in updaters. It enables ad fraud and proxy botnets through multi-stage downloads.

TL;DR

  • Kaspersky discovered Android car malware in June 2026.
  • Targets DoFun-developed head unit firmware.
  • Spreads through built-in updater mechanisms.
  • Aims to commit ad fraud and build proxy botnets.
  • Uses a multi-stage downloader for malicious payloads.

Cybersecurity researchers at Kaspersky have uncovered a new form of malware specifically targeting Android-based vehicle head units. The malicious software exploits built-in updater systems to infiltrate firmware developed by DoFun, raising serious concerns for automotive cybersecurity.

Once installed, the malware acts as a multi-stage downloader, paving the way for fraudulent advertising activities and the creation of a proxy botnet. This discovery highlights the expanding threat landscape in connected vehicles and the critical need for secure update mechanisms in embedded systems.

Attack Vector and Distribution

  • The malware spreads through legitimate-looking updates from built-in updater services.
  • Specifically targets firmware developed by DoFun for vehicle infotainment systems.
  • Infection occurs without user interaction by masquerading as official system updates.

Malicious Capabilities

  • Installs a multi-stage downloader to fetch additional malicious components.
  • Enables large-scale ad fraud operations by hijacking device traffic.
  • Creates proxy botnet nodes that can route malicious network traffic.
  • Potentially allows persistent access to vehicle network systems.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Android Car Malware Exploits Firmware Updaters — Agent Breach Blog | Agent Breach