Kaspersky research has identified a sophisticated Trojan targeting Android-based automotive head units specifically utilizing DoFun firmware. The infection vector exploits compromised Over-the-Air (OTA) software update mechanisms, allowing for the deployment of trojanized firmware packages. Upon infection, a multi-stage downloader executes payloads that integrate the vehicle's infotainment system into a distributed proxy botnet. This botnet is primarily leveraged for large-scale automated ad fraud operations, utilizing the vehicle's unique IP address to mask malicious traffic. The campaign represents a significant shift toward weaponizing connected vehicle infrastructure for distributed computing and economic gain, while presenting critical lateral movement risks to vehicle control systems.
-
Incident Overview: Automotive Botnet Emergence
- Discovery of specialized Android-based malware by Kaspersky/Securelist in June 2026.
- Targeted exploitation of DoFun manufacturer firmware used in various car head units.
- Shift in threat landscape from individual vehicle sabotage to large-scale remote-access botnets.
-
Attack Vector: Supply Chain & OTA Vulnerabilities
- Exploitation of legitimate manufacturer software update pathways to bypass traditional security.
- Deployment of trojanized firmware packages via compromised automated update modules.
- Utilization of multi-stage downloader payloads to establish persistence within the infotainment OS.
-
Payload Mechanics: Proxy Botnet Orchestration
- Integration of infected head units into a distributed proxy botnet architecture.
- Use of dedicated Command and Control (C2) infrastructure to manage hijacked vehicle nodes.
- Execution of automated ad fraud scripts to generate revenue through fraudulent traffic.
-
Impact Analysis: Economic and Safety Risks
- Economic impact: Massive revenue generation via large-scale automated ad fraud.
- Network evasion: Using consumer vehicle IP addresses to mask malicious traffic origins.
- Critical safety risk: Potential for lateral movement from the infotainment system to the vehicle's CAN bus.
-
Defensive Implications: Industry Response
- Requirement for cryptographically secure OTA update mechanisms and firmware signing.
- Necessity for strict network segmentation between infotainment systems and driving-critical controllers.
- Enhanced monitoring for anomalous outbound network traffic originating from connected vehicle hardware.
Related posts
- Kaspersky Daily — Malware in car infotainment systems: how infection occurs | Kaspersky official blog
- feeds.feedburner.com — Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
- Pcmag
- Bworldonline
- Securelist
- Pmc
- Trendaisecurity
- Upstream
- Mdpi
- Prnewswire
- Mcafee
- Iris
- Trendmicro