Home: Motoring > Kaspersky Uncovers Malware Hijack Risk in DoFun Android Auto Systems

Kaspersky Uncovers Malware Hijack Risk in DoFun Android Auto Systems

From:Internet Info Agency 2026-08-30 20:15:09

Kaspersky security researchers have discovered a new type of malware capable of compromising Android-based in-vehicle infotainment (IVI) systems running software developed by the Chinese company DoFun. The malware exploits the preinstalled TWCore system service on affected vehicles to install a malicious file named JarService, which then decrypts and launches a secondary-stage malicious downloader. This downloader connects to a command-and-control (C2) server, enabling attackers to collect information such as the vehicle’s IVI model, screen resolution, Wi-Fi network details, and MAC address, and to remotely execute commands—including opening web pages and downloading and running additional malicious code. Compromised devices could potentially be enrolled into a botnet, used as proxy servers to relay traffic, or leveraged to launch other cyberattacks. These capabilities are provided by a payload named "zhima." Kaspersky’s investigation revealed links between the threat actor MoYu Group and residential proxy services PXYEDGE and ProxyForU. Globally, over 30 million vehicles could theoretically be affected. The attack requires the IVI system to be connected to the internet; vehicles using only offline functionality remain unaffected. The vendor has released a patch addressing the vulnerability in the TWCore service and urges users to immediately install the latest software version. If no update option is available, users should contact their vehicle manufacturer for a patched firmware update.

Editor:NewsAssistant