Android Malware Turns Car Infotainment Systems Into Ad Fraud Botnet
Kaspersky researchers discovered a campaign targeting DoFun head units via a vulnerability in system update software.
Security researchers at Kaspersky have discovered a novel Android malware campaign targeting vehicle infotainment modules, marking a significant expansion in the reach of automotive-based botnets. The malware, identified as JarService, targets head units manufactured by the Chinese company DoFun to recruit vehicles into a wider network for fraudulent activity.
The infection chain leverages a critical weakness in the 'TWCore' application, a system tool used for firmware updates on these devices. Once the vulnerability is exploited, the malware operates as a multi-stage downloader. According to Kaspersky, the payload deploys two primary components: a Trojan clicker designed to conduct click fraud and a reverse-proxy module. The researchers attributed the campaign to the MoYu Group—the actors responsible for the BadBox botnet—with high confidence, citing technical overlaps with the group's existing ad fraud infrastructure.
The New Automotive Attack Surface
Car head units are essentially Internet-connected Android-based modules that manage a vehicle's entertainment and navigation systems. While these modules are integrated into the dashboard, the specific units targeted in this campaign are purely infotainment systems. This means that while the devices are compromised, the infection does not grant the attackers control over critical vehicle functions, posing no direct physical risk to drivers or passengers.
However, the method of delivery is particularly concerning. Dmitry Kalinin, a security researcher at Kaspersky, noted that this case demonstrates a sophisticated delivery method by distributing the malware through the legitimate update functionality of a system application. This allows the attackers to bypass traditional security assumptions by using the device's own trusted update mechanism to install malicious code.
Implications for the Supply Chain
This campaign represents a strategic shift in botnet evolution. Historically, actors like the MoYu Group have targeted home IoT devices, such as connected televisions, to build their proxy networks. Moving into automotive systems demonstrates that attackers are actively seeking new, under-secured hardware to expand their infrastructure.
Furthermore, this is the first documented case of malware found on a car head unit with an infection chain specifically tailored to that device type. It highlights a growing vulnerability in the automotive supply chain, where third-party Android-based hardware may lack the rigorous security auditing found in primary vehicle control systems.
What to Watch
As automotive systems become more integrated and reliant on third-party software, the risk of supply chain attacks is likely to increase. The industry must now address the security of non-critical infotainment modules to prevent them from becoming permanent footholds for cybercriminals. For now, the primary goal of the MoYu Group remains financial gain through ad fraud, but the establishment of reverse proxies on vehicle hardware could potentially be used for more clandestine network activities in the future.