Indonesian Political, Business & Finance News

5 Risks of Android Car Head Units Targeted by Malware

| | Source: MEDIA_INDONESIA Translated from Indonesian | Technology
5 Risks of Android Car Head Units Targeted by Malware
Image: MEDIA_INDONESIA

KASPERSKY revealed shocking findings on 21 August 2026 regarding malware attacks specifically targeting Android-based car head units. This case, first detected in June 2026, marks a historical milestone as the first attack to enter through automated software (firmware) update mechanisms.

The attack specifically targets devices using the ecosystem of DoFun, a Chinese company that provides cloud services and firmware to more than 30 million vehicle owners worldwide.

Attackers exploit a vulnerability in an official system application named TWCore to inject a malicious component called JarService without requiring any interaction or consent from the car owner.

Below are the primary risks faced by vehicle owners if their head units become infected:

Performance degradation is the most immediate risk, with head units becoming slow, lagging, or unstable. This occurs because computing resources, such as the CPU and RAM, are consumed by the malware to run background processes.

Additionally, the vehicle’s internet connection speed will drop drastically as bandwidth is diverted to the attackers’ illegal activities.

Through a module named ‘zhima’, this malware transforms the head unit into part of a botnet network. This means your vehicle’s internet connection is used as an internet traffic pathway for third parties.

A serious risk is that your IP address may be recorded performing suspicious or illegal cyber activities conducted by botnet operators, making it appear as though such activities originated from the vehicle owner.

The malware actively collects and transmits sensitive information to command-and-control (C2) servers. The data harvested includes device models, screen resolution, connected Wi-Fi SSIDs, and MAC addresses.

This information provides a profile of the user and their network, which can be utilised for more targeted subsequent attacks.

Although the malware is currently detected being used for ad-fraud and proxy services, Kaspersky warns of the capability to download and execute additional code. Technically, operators can change the malware’s function at any time by sending new payloads that may have more dangerous objectives in the future.

To date, there is no evidence that the malware can take control of critical safety systems such as brakes, steering, or the engine. The attack focuses on exploiting the computing and network resources of the infotainment system.

As a technical clarification, Kaspersky’s original report identifies the detection of this malware as Trojan-Dropper AndroidOS Agent and Vo1d, rather than ‘PlayPraetor’ as initially circulated in some early reports. PlayPraetor itself is a different type of threat targeting banking applications and is unrelated to the attack chain on these DoFun head units.

View JSON | Print