← Back to Daily Briefing (#cratesio)

Kaspersky research has identified a sophisticated Trojan targeting Android-based automotive head units specifically utilizing DoFun firmware. The infection vector exploits compromised Over-the-Air (OTA) software update mechanisms, allowing for the deployment of trojanized firmware packages. Upon infection, a multi-stage downloader executes payloads that integrate the vehicle's infotainment system into a distributed proxy botnet. This botnet is primarily leveraged for large-scale automated ad fraud operations, utilizing the vehicle's unique IP address to mask malicious traffic. The campaign represents a significant shift toward weaponizing connected vehicle infrastructure for distributed computing and economic gain, while presenting critical lateral movement risks to vehicle control systems.

  • Incident Overview: Automotive Botnet Emergence

    • Discovery of specialized Android-based malware by Kaspersky/Securelist in June 2026.
    • Targeted exploitation of DoFun manufacturer firmware used in various car head units.
    • Shift in threat landscape from individual vehicle sabotage to large-scale remote-access botnets.
  • Attack Vector: Supply Chain & OTA Vulnerabilities

    • Exploitation of legitimate manufacturer software update pathways to bypass traditional security.
    • Deployment of trojanized firmware packages via compromised automated update modules.
    • Utilization of multi-stage downloader payloads to establish persistence within the infotainment OS.
  • Payload Mechanics: Proxy Botnet Orchestration

    • Integration of infected head units into a distributed proxy botnet architecture.
    • Use of dedicated Command and Control (C2) infrastructure to manage hijacked vehicle nodes.
    • Execution of automated ad fraud scripts to generate revenue through fraudulent traffic.
  • Impact Analysis: Economic and Safety Risks

    • Economic impact: Massive revenue generation via large-scale automated ad fraud.
    • Network evasion: Using consumer vehicle IP addresses to mask malicious traffic origins.
    • Critical safety risk: Potential for lateral movement from the infotainment system to the vehicle's CAN bus.
  • Defensive Implications: Industry Response

    • Requirement for cryptographically secure OTA update mechanisms and firmware signing.
    • Necessity for strict network segmentation between infotainment systems and driving-critical controllers.
    • Enhanced monitoring for anomalous outbound network traffic originating from connected vehicle hardware.

Related posts

  1. Kaspersky Daily — Malware in car infotainment systems: how infection occurs | Kaspersky official blog
  2. feeds.feedburner.com — Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
  3. Pcmag
  4. Bworldonline
  5. Securelist
  6. Pmc
  7. Trendaisecurity
  8. Upstream
  9. Mdpi
  10. Prnewswire
  11. Mcafee
  12. Iris
  13. Trendmicro

LINK COPIED TO CLIPBOARD