Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Executive Summary
Kaspersky identified a new Android-based vehicle head‑unit malware family in June 2026 that targets firmware from DoFun. The code uses the device’s built‑in updater to deliver a multi‑stage downloader, enabling ad‑fraud operations and the creation of a proxy botnet. The threat demonstrates how automotive software updates can be weaponised to compromise in‑vehicle systems.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-21T15:41:44+00:00 - Category: threat-intel
Original Description: Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of
"Fortune favours the brave."
— Virgil