Android car head units compromised by firmware update malware campaign

Cybersecurity researchers reported on August 22–23, 2026, that hackers compromised Android-based car infotainment systems (DoFun head units) through a legitimate firmware update app, enlisting devices in a proxy botnet for ad fraud and proxy operations. The supply-chain attack was first discovered by Kaspersky.

8 reports · 7 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Kaspersky discovers first Android malware targeting car infotainment systems. DoFun head units compromised via firmware updater to become ad-fraud and proxy botnet nodes. https:// deafnews.it/en/artic

mastodon:infosec-exchangeother39d ago kagi ↗

Kaspersky discovers first Android malware targeting car infotainment systems. DoFun head units compromised via firmware updater to become ad-fraud and proxy botnet nodes. https:// deafnews.it/en/article/android -malware-in-car-head-units-vehicles-become-gig-economy-nodes

Kaspersky has identified a new malware family targeting Android car head units from DoFun. The malware abuses built-in OTA updaters to deploy ad fraud toolkits and proxy botnet infrastructure. # Suppl

mastodon:infosec-exchangeother38d ago kagi ↗

Kaspersky has identified a new malware family targeting Android car head units from DoFun. The malware abuses built-in OTA updaters to deploy ad fraud toolkits and proxy botnet infrastructure. # SupplyChainAttack # ProxyBotnet # AutomotiveSecurity # AdFraud https:// cyberworldops.eu/en/malware-in -android-car-head-units-updates-become-a-channel-for-ad

Researchers detail malware campaigns affecting WordPress sites, car systems and banking users

kite:techother38d ago kagi ↗

Cybersecurity researchers reported several active malware operations affecting websites, vehicle infotainment systems and financial users. Check Point Research's StopAndProtect investigation identified a cybercrime network using 2,000 hijacked WordPress domains. TechRadar reported that outdated WordPress installations and third-party plugins helped the operation succeed [techradar.com#1]. Kaspersk

🤖 Supply-chain attack targets Android car head units: malware spreads via a legitimate device-update app, enlisting compromised units in a proxy botnet or using them for ad fraud. Head units with net

mastodon:infosec-exchangeother38d ago kagi ↗

🤖 Supply-chain attack targets Android car head units: malware spreads via a legitimate device-update app, enlisting compromised units in a proxy botnet or using them for ad fraud. Head units with network access become stealthy proxies — a growing IoT abuse vector. 🔗 https://www. bleepingcomputer.com/news/secu rity/hackers-infect-android-car-head-units-with-proxy-botnet-malware/ # Malware # Cyber

🤖 Supply-chain attack on Android car head units: a legitimate device-update app is abused to push proxy botnet malware, recruiting compromised units for proxy traffic and ad fraud. 🔗 https://www. bl

mastodon:infosec-exchangeother37d ago kagi ↗

🤖 Supply-chain attack on Android car head units: a legitimate device-update app is abused to push proxy botnet malware, recruiting compromised units for proxy traffic and ad fraud. 🔗 https://www. bleepingcomputer.com/news/secu rity/hackers-infect-android-car-head-units-with-proxy-botnet-malware/ # Malware # SupplyChain # CyberSec

🤖 Supply-chain attack: Android car head units compromised via a legitimate device-update app that installs malware, enlisting devices in a proxy botnet and running ad fraud. Compromised units abused

mastodon:infosec-exchangeother37d ago kagi ↗

🤖 Supply-chain attack: Android car head units compromised via a legitimate device-update app that installs malware, enlisting devices in a proxy botnet and running ad fraud. Compromised units abused for traffic relay. 🔗 https://www. bleepingcomputer.com/news/secu rity/hackers-infect-android-car-head-units-with-proxy-botnet-malware/ # Malware # Botnet # SupplyChain # CyberSec