Android Car Infotainment Systems Hit by Silent Malware Threat

Last month, Kaspersky researchers identified a stealthy Android malware campaign that turns car infotainment systems into anonymous proxy nodes for ad fraud. The attack exploits the official update mechanism of Android-based head units, installing a silent dropper that avoids detection and transforms the device into part of the BADBOX botnet.
A Gateway Hidden in Plain Sight
Modern car infotainment systems run on Android for cost and flexibility, allowing manufacturers to customize the platform without building from scratch. But this convenience comes with a blind spot: any smartphone-compatible app can technically run on a head unit, including malware. In June 2026, Kaspersky discovered an Android app with no user interface, installed like any other app but designed solely to decrypt and load subsequent malicious stages. The infection chain begins with TWCore, a legitimate analytics and update app found in DoFun-branded head units. Attackers abuse TWCore’s MQTT-based update system by flipping a configuration flag called installNotExists, turning a routine firmware update channel into a silent installation pipeline for arbitrary APKs.
From Dropper to Botnet Node
The first payload, JarService, acts as a minimal dropper with no visible interface. It decrypts and loads a second-stage loader, which then contacts a command server, reports device details, and fetches the final payload—a reverse proxy and ad-click module. Researchers observed at least seven versions of this payload, suggesting the attackers continuously refine their tools. Once installed, the malware checks in every 90 minutes, waiting for instructions to generate fraudulent ad clicks or route traffic through the compromised device.
Why it matters
This marks the first documented malware targeting car head units, exposing a critical attack surface in connected vehicles. While the payload appears focused on ad fraud, the same infection chain could deliver more damaging payloads—from data theft to remote control of vehicle functions. Manufacturers must harden their update pipelines and audit system apps like TWCore, while drivers should ensure their infotainment systems run the latest firmware and avoid side-loading apps. The episode underscores how the Android ecosystem’s flexibility, when combined with weak update controls, can turn car entertainment systems into unwitting bots in a global network.
Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

