Skip to content
First malware targeting vehicle infotainment systems discovered

First malware targeting vehicle infotainment systems discovered

Escudodigital • August 22, 2026

Cybercrime hits the dashboard: A vulnerability in Android updates lets attackers secretly install malicious code, extract technical data, and execute ad fraud.

A novel malicious software campaign targeting Android specifically for vehicle smart screens has been detected by the research team at cybersecurity company Kaspersky. These systems, which sometimes combine multimedia entertainment and key car controls, have become the new target for cybercriminals.

The cybercriminals use a stealthy multi-stage download program , marking the first documented case of this type of harmful computer code infecting a vehicle's multimedia screen through an infection chain exclusively adapted to these automotive systems.

The main objective of the cybercriminals is to deploy malicious code to commit massive advertising fraud and other harmful activities. According to experts, this activity may be linked to MoYu Group , a cyber threat actor closely related to the well-known infected device network BadBox .

Car multimedia screens, whether factory-installed or added later, commonly use the Android operating system to customize the interface and add key functions. This allows most Android applications and malware to run on them.

Although these devices rarely store sensitive personal data, they have SIM card slots and continuous internet connection for map and updates, making them an attractive entry point for cybercriminals.

The malicious software was distributed by exploiting the update mechanisms integrated into the software of several models of Android screens from provider DoFun , which claims to have already fixed the vulnerability following Kaspersky's notification. The infection chain was caused in the legitimate system application TWCore , responsible for collecting analytics and managing device updates.

The cybercriminals manipulated this channel to directly deliver a hidden installation program called JarService , which operated in the background without a user interface and without the driver noticing anything unusual. Once inside, the cybercriminals had nine different commands capable of displaying unwanted ads, executing advertising fraud, and downloading additional harmful modules. Additionally, the malicious software collected technical information the vehicle, such as screen resolution, model, connected wifi network, and the physical address of the device.

Kaspersky also identified that the infrastructure of this cyberattack shares code and administration panels with illegal intermediary server services related to BadBox, a massive network of infected Android devices used to divert unauthorized traffic and steal data.

A novel malicious software campaign targeting Android specifically for vehicle smart screens has been detected by the research team at cybersecurity company Kaspersky. These systems, which sometimes combine multimedia entertainment and key car controls, have become the new target for cybercriminals.

The cybercriminals use a stealthy multi-stage download program , marking the first documented case of this type of harmful computer code infecting a vehicle's multimedia screen through an infection chain exclusively adapted to these automotive systems.

The main objective of the cybercriminals is to deploy malicious code to commit massive advertising fraud and other harmful activities. According to experts, this activity may be linked to MoYu Group , a cyber threat actor closely related to the well-known infected device network BadBox .

Car multimedia screens, whether factory-installed or added later, commonly use the Android operating system to customize the interface and add key functions. This allows most Android applications and malware to run on them.

Although these devices rarely store sensitive personal data, they have SIM card slots and continuous internet connection for map and updates, making them an attractive entry point for cybercriminals.

The malicious software was distributed by exploiting the update mechanisms integrated into the software of several models of Android screens from provider DoFun , which claims to have already fixed the vulnerability following Kaspersky's notification. The infection chain was caused in the legitimate system application TWCore , responsible for collecting analytics and managing device updates.

The cybercriminals manipulated this channel to directly deliver a hidden installation program called JarService , which operated in the background without a user interface and without the driver noticing anything unusual. Once inside, the cybercriminals had nine different commands capable of displaying unwanted ads, executing advertising fraud, and downloading additional harmful modules. Additionally, the malicious software collected technical information the vehicle, such as screen resolution, model, connected wifi network, and the physical address of the device.

Kaspersky also identified that the infrastructure of this cyberattack shares code and administration panels with illegal intermediary server services related to BadBox, a massive network of infected Android devices used to divert unauthorized traffic and steal data.

Become a premium member for free!

Extracted Entities

Attack Types (1)

Malware (1)

Platforms (1)