Car Dashboard Screens Were Infected Through Their Own Update App, Kaspersky Says

Kaspersky said Aug. 21 that it had found Android malware on car head units, the dashboard systems that run navigation and media, and that the malware reached them through the units' own built-in software updater. The company says the affected units are made by DoFun.
Kaspersky says the malware is a multi-stage downloader whose purpose is advertising fraud and building a proxy botnet, a network of internet connections rented out to route someone else's traffic. Its report does not say how many devices were affected, and gives no geographic breakdown.
The delivery route was TWCore, a legitimate system application on the units that collects analytics data and installs software updates, according to the report. Kaspersky says it notified the device vendor about the distribution scheme and that the vendor "subsequently reported fixing the security issues." Kaspersky publishes the names its products use to detect the components, which it calls JarService and, for a later reverse-proxy module, zhima.
The company attributes the activity "with high confidence" to what it calls the MoYu Group, an actor it links to the BADBOX botnet, citing naming patterns it found in the code and an overlap in network infrastructure. It says researchers at the Nokia Deepfield Emergency Response Team independently identified that infrastructure, and found the same reverse-proxy module on TV set-top boxes, at around the same time.
Kaspersky describes the case as "the first documented case of malware found on a car head unit with an infection chain specific to that type of device."
The malware was found in June 2026 during Kaspersky's routine monitoring of Android threats, the report says. It was written by Dmitry Kalinin and published on the company's Securelist research blog.
