Skip to content
See the World Through Science

Car Dashboard Screens Were Infected Through Their Own Update App, Kaspersky Says

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

An illuminated aftermarket head unit fitted into a car dashboard, its display reading BT AUDIO above a row of preset buttons and heater controls.
An aftermarket head unit in a car dashboard. Kaspersky's case concerns head units of this slot, but a newer, Android-based generation: full computers that fetch their own updates. Illustrative: a Sony CD receiver, not one of the DoFun units in the report."Sony Car-CD illuminated (cropped)" by Zuzu, via wikimedia, CC-BY-SA-3.0 · CC-BY-SA-3.0

Kaspersky said Aug. 21 that it had found Android malware on car head units, the dashboard systems that run navigation and media, and that the malware reached them through the units' own built-in software updater. The company says the affected units are made by DoFun.

Kaspersky says the malware is a multi-stage downloader whose purpose is advertising fraud and building a proxy botnet, a network of internet connections rented out to route someone else's traffic. Its report does not say how many devices were affected, and gives no geographic breakdown.

The delivery route was TWCore, a legitimate system application on the units that collects analytics data and installs software updates, according to the report. Kaspersky says it notified the device vendor about the distribution scheme and that the vendor "subsequently reported fixing the security issues." Kaspersky publishes the names its products use to detect the components, which it calls JarService and, for a later reverse-proxy module, zhima.

The company attributes the activity "with high confidence" to what it calls the MoYu Group, an actor it links to the BADBOX botnet, citing naming patterns it found in the code and an overlap in network infrastructure. It says researchers at the Nokia Deepfield Emergency Response Team independently identified that infrastructure, and found the same reverse-proxy module on TV set-top boxes, at around the same time.

Kaspersky describes the case as "the first documented case of malware found on a car head unit with an infection chain specific to that type of device."

The malware was found in June 2026 during Kaspersky's routine monitoring of Android threats, the report says. It was written by Dmitry Kalinin and published on the company's Securelist research blog.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Car Dashboard Screens Were Infected Through Their Own Update App, Kaspersky Says

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.