Kaspersky Exposes Car Head Unit Botnet Spread via Legitimate Firmware Updater
Kaspersky disclosed in June 2026 that a botnet campaign targeted DoFun-based Android car head units by exploiting the device's own legitimate firmware update system, TWCore, rather than any software vulnerability. Attackers used TWCore's update pipeline to silently push a hidden app called JarService, which turned infected units into click fraud bots and residential proxy exits. The campaign is attributed to MoYu Group, the same threat actor linked to the BADBOX TV box botnet that Google sued over in July 2025. DoFun, whose firmware powers aftermarket infotainment systems in over 30 million vehicles, has since closed the abused update pathway, but patching remains uncertain given the fragmented reseller supply chain. Owners can check for infection via ADB commands or by monitoring network traffic for suspicious outbound activity, and are advised to isolate affected units on a separate network segment.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in