Kaspersky revealed it discovered in June 2026 the first documented malware campaign specifically targeting Android-based automotive multimedia systems. The attack exploited the system's own update mechanism to install the JarService malware without any driver intervention. The infection occurred through a legitimate application called TWCore, used to manage updates on multimedia units with software from Chinese company DoFun.
The malware remained completely discreet, presenting no visible interface or requiring user authorization. After installation, JarService established communication with servers controlled by cybercriminals and could download additional components. The attackers managed to collect information from the infected device, including model, screen resolution, MAC address, and Wi-Fi network data, as well as being able to generate fraudulent clicks on ads to produce illegal revenue.
The investigators also discovered that attackers could install a module called "zhima," turning the car's multimedia system into part of a botnet. This network allowed the use of the device's resources, including its internet connection, to route third-party traffic without the owner's knowledge. Kaspersky identified nine commands available to the cybercriminals, including ad fraud and downloading additional malicious modules.
The campaign was associated with the MoYu group, linked to the criminal operation BadBox, which had already compromised television boxes, smartphones, and tablets. After being informed by Kaspersky, DoFun stated the problem was fixed. However, the cybersecurity company warns that automotive multimedia systems should be treated as internet-connected devices, exposed to risks similar to those of other Android devices, and recommends that updates be installed only through official manufacturer mechanisms.




