Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Summary
Cybersecurity researchers have identified a new malware family targeting Android-based vehicle head units manufactured by DoFun. This malware, discovered in June 2026 by Kaspersky, aims to facilitate ad fraud and establish a proxy botnet by employing a multi-stage downloader. The threat spreads via the vehicles' built-in update mechanisms.
IFF Assessment
This malware is bad news for defenders as it represents a new attack vector and capability targeting connected vehicles, which could lead to financial losses and compromised network resources.
Defender Context
This discovery highlights a growing concern for the security of automotive infotainment systems, which are increasingly becoming targets for sophisticated malware. Defenders should be aware of potential vulnerabilities in vehicle firmware update mechanisms and the evolving threat landscape of connected car malware, focusing on securing these complex ecosystems.