{
    "success": true,
    "data": {
        "id": 1954892,
        "msgid": "5-risks-of-android-car-head-units-targeted-by-malware-1788335581",
        "date": "2026-09-02 14:00:00",
        "title": "5 Risks of Android Car Head Units Targeted by Malware",
        "author": "Gana Buana",
        "source": "MEDIA_INDONESIA",
        "tags": "",
        "topic": "Technology",
        "summary": "Cybersecurity firm Kaspersky has revealed a significant malware threat targeting Android-based car head units via automated firmware updates. The attack exploits vulnerabilities in the DoFun ecosystem, potentially turning vehicles into nodes within a botnet.",
        "content": "<p>KASPERSKY revealed shocking findings on 21 August 2026 regarding\nmalware attacks specifically targeting Android-based car head units.\nThis case, first detected in June 2026, marks a historical milestone as\nthe first attack to enter through automated software (firmware) update\nmechanisms.<\/p>\n<p>The attack specifically targets devices using the ecosystem of DoFun,\na Chinese company that provides cloud services and firmware to more than\n30 million vehicle owners worldwide.<\/p>\n<p>Attackers exploit a vulnerability in an official system application\nnamed TWCore to inject a malicious component called JarService without\nrequiring any interaction or consent from the car owner.<\/p>\n<p>Below are the primary risks faced by vehicle owners if their head\nunits become infected:<\/p>\n<p>Performance degradation is the most immediate risk, with head units\nbecoming slow, lagging, or unstable. This occurs because computing\nresources, such as the CPU and RAM, are consumed by the malware to run\nbackground processes.<\/p>\n<p>Additionally, the vehicle\u2019s internet connection speed will drop\ndrastically as bandwidth is diverted to the attackers\u2019 illegal\nactivities.<\/p>\n<p>Through a module named \u2018zhima\u2019, this malware transforms the head unit\ninto part of a botnet network. This means your vehicle\u2019s internet\nconnection is used as an internet traffic pathway for third parties.<\/p>\n<p>A serious risk is that your IP address may be recorded performing\nsuspicious or illegal cyber activities conducted by botnet operators,\nmaking it appear as though such activities originated from the vehicle\nowner.<\/p>\n<p>The malware actively collects and transmits sensitive information to\ncommand-and-control (C2) servers. The data harvested includes device\nmodels, screen resolution, connected Wi-Fi SSIDs, and MAC addresses.<\/p>\n<p>This information provides a profile of the user and their network,\nwhich can be utilised for more targeted subsequent attacks.<\/p>\n<p>Although the malware is currently detected being used for ad-fraud\nand proxy services, Kaspersky warns of the capability to download and\nexecute additional code. Technically, operators can change the malware\u2019s\nfunction at any time by sending new payloads that may have more\ndangerous objectives in the future.<\/p>\n<p>To date, there is no evidence that the malware can take control of\ncritical safety systems such as brakes, steering, or the engine. The\nattack focuses on exploiting the computing and network resources of the\ninfotainment system.<\/p>\n<p>As a technical clarification, Kaspersky\u2019s original report identifies\nthe detection of this malware as Trojan-Dropper AndroidOS Agent and\nVo1d, rather than \u2018PlayPraetor\u2019 as initially circulated in some early\nreports. PlayPraetor itself is a different type of threat targeting\nbanking applications and is unrelated to the attack chain on these DoFun\nhead units.<\/p>",
        "url": "https:\/\/jawawa.id\/newsitem\/5-risks-of-android-car-head-units-targeted-by-malware-1788335581",
        "image": ""
    },
    "sponsor": "Okusi Associates",
    "sponsor_url": "https:\/\/okusiassociates.com"
}