Recently, cybersecurity researchers have uncovered a new family of malware specifically designed to infect the firmware of Android-based car head units developed by DoFun. This malware spreads through legitimate device update applications, aiming to create a proxy botnet and facilitate ad fraud. Kaspersky's research indicates that this is the first documented case of a malware infection chain specifically targeting car head units. The malware, identified as JarService, operates in the background, collecting device information and executing commands for ad fraud. It was found that the malware does not interfere with driving or critical vehicle control systems, but rather focuses on monetizing the compromised devices by turning them into residential proxy nodes. This incident highlights the urgent need for robust cybersecurity measures in modern automotive platforms to prevent such targeted attacks.
Industry Insights · August 23, 2026
Android Car Head Units Infected with Proxy Botnet Malware
Researchers have identified malware infecting Android car head units via update mechanisms, creating a proxy botnet.
