Interestana
Home/News/Android Car Malware Targets DoFun Firmware for Ad Fraud
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Android Car Malware Targets DoFun Firmware for Ad Fraud

Android Car Malware Targets DoFun Firmware for Ad Fraud

Cybersecurity researchers have identified a novel malware family specifically engineered to compromise the firmware of Android-based vehicle head units developed by DoFun. Kaspersky, the cybersecurity firm that uncovered this threat in June 2026, detailed that the malware's ultimate objective is to deploy a multi-stage downloader. This downloader facilitates ad fraud and the establishment of a proxy botnet, effectively turning infected vehicles into nodes for malicious network activities. The malware's propagation mechanism leverages the built-in update functionalities of the affected firmware, allowing it to spread discreetly. This method of distribution bypasses typical security measures that users might employ for their mobile devices, making it particularly insidious for automotive systems.

The DoFun firmware is utilized in the infotainment systems of various vehicles, suggesting a broad potential attack surface for this malware. By compromising these systems, the attackers can manipulate the display of advertisements within the vehicle's interface, generating fraudulent revenue. Furthermore, the creation of a proxy botnet allows threat actors to route their malicious traffic through the compromised vehicles. This can be used to mask the origin of other cyberattacks, conduct distributed denial-of-service (DDoS) attacks, or engage in other illicit online activities, all while appearing to originate from legitimate vehicle IP addresses. The sophistication of this attack highlights the growing vulnerability of connected automotive systems to advanced cyber threats.

Kaspersky's analysis indicates that the malware operates in several stages. Initially, it gains a foothold by exploiting vulnerabilities within the DoFun firmware's update process. Once installed, it downloads and executes further malicious payloads. These payloads are designed to manage the ad fraud operations, which likely involve displaying deceptive advertisements or redirecting users to malicious websites. Simultaneously, the malware establishes its presence as a proxy server, making the infected vehicle an unwitting participant in a larger botnet infrastructure. The researchers have not yet disclosed the specific vulnerabilities exploited, but the reliance on built-in updaters points to a potential weakness in the firmware's security protocols or the update delivery mechanism itself. The implications for vehicle owners are significant, ranging from financial losses due to ad fraud to potential privacy concerns and the risk of their vehicle being used in criminal activities without their knowledge.

This discovery underscores the increasing need for robust cybersecurity measures in the automotive sector. As vehicles become more integrated with digital technologies and rely on complex software for their operations, they present attractive targets for cybercriminals. The use of built-in updaters as an attack vector is a concerning development, as it exploits a feature intended for system improvement and security patching. Companies like DoFun, which provide firmware for automotive infotainment systems, face immense pressure to ensure the integrity and security of their software supply chains. The potential for widespread infection across multiple vehicle models that utilize the compromised firmware necessitates swift action from manufacturers and cybersecurity firms to develop and deploy patches to mitigate the threat.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next