Android-Based DoFun Infotainment Malware: Supply Chain Exploitation for Ad Fraud Botnets
Kaspersky research has identified a sophisticated Trojan targeting Android-based automotive head units specifically utilizing DoFun firmware. The infection vector exploits compromised Over-the-Air (OTA) software update mechanisms, allowing for the deployment of trojanized firmware packages. Upon infection, a multi-stage downloader executes payloads that integrate the vehicle's infotainment system into a distributed proxy botnet. This botnet is primarily leveraged for large-scale automated ad fraud operations, utilizing the vehicle's unique IP address to mask malicious traffic. The campaign represents a significant shift toward weaponizing connected vehicle infrastructure for distributed computing and economic gain, while presenting critical lateral movement risks to vehicle control systems.