CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

First car head unit malware hides inside Android update channel

Kaspersky finds the first Android malware built for car head units, delivered through the devices' own update channel.

CarThreat Staff
Last updated: August 22, 2026 9:52 pm
By
ctadmin
2 Min Read
SHARE

Kaspersky has documented what it calls the first Android malware campaign built specifically for car head units, a family that hitches a ride on the devices’ legitimate update channel to plant ad fraud and proxy botnet code.

The malware targets infotainment firmware developed by DoFun, which powers aftermarket head units and some factory-built systems. Researchers found it distributed through the update mechanism of a system app called TWCore, which normally fetches analytics and APK updates over an MQTT broker hosted on a cardoor.cn subdomain. Attackers weaponized that channel to drop a loader named JarService, which installs a covert payload that reports to a command-and-control endpoint every 90 minutes.

Security researcher Dmitry Kalinin said this is the first documented case of malware on a car head unit with an infection chain specific to that device type. Kaspersky attributes the campaign with high confidence to the MoYu Group, the crew behind the BADBOX ad fraud and residential proxy scheme that Google sued over in July 2025.

Head units are an attractive target because they sit at the center of the cockpit, blend multimedia with partial vehicle control, and carry a SIM slot for navigation and updates. Kalinin noted that delivery methods keep evolving, from pre-installed backdoors to compromised apps, and that this case abused the software update functionality of a legitimate system component. The vendor addressed the flaw after responsible disclosure, and owners should install the latest firmware while treating head unit app sources with the same caution as smartphone downloads.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesFirmware SecurityInfotainment SystemsMalwareOTA UpdatesRemote Code Execution (RCE)Threat IntelligenceVehicle Software
SOURCES:The Hacker News
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

BYD Xuanji A3 Chip Targets First Vehicle Deployment by 2027

By
ctadmin
July 1, 2026
Cybersecurity

ECARX and TPK Partner on ORCA LiDAR Platform Targeting ADAS and Robotaxi Security

By
ctadmin
May 30, 2026
Cybersecurity

Lightweight detector catches rogue cars broadcasting fake safety data

By
ctadmin
August 13, 2026
Cybersecurity

Researchers weaponize digital license plates against plate readers

By
ctadmin
August 10, 2026
Electric Vehicles

Fake plug-and-charge stations bill EV owners for stranger fills

By
ctadmin
August 9, 2026
Cybersecurity

Infineon Pushes EV Inverter Thermal Limits With 205°C SiC Module

By
ctadmin
May 29, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?