Executive Summary

A new malware family has been discovered targeting Android-based vehicle head unit firmware developed by DoFun. The malware, discovered by Kaspersky in June 2026, spreads through built-in updaters and enables ad fraud and creation of a proxy botnet. This threat has a moderate to high severity level.

Technical Analysis

The malware is designed to infect Android-based vehicle head unit firmware developed by DoFun. Its primary goal is to serve a multi-stage downloader, which enables ad fraud and creation of a proxy botnet. The malware spreads through the built-in updaters of the affected firmware.

How It Gets Exploited

An attacker would likely exploit this vulnerability by first gaining access to the vehicle's head unit firmware updater. This could be done through various means, such as a supply chain attack or by compromising the updater software. Once the updater is compromised, the attacker can push the malware to the vehicle's head unit, which would then be infected. The malware would then enable ad fraud and creation of a proxy botnet.

Impact Assessment

The impact of this malware is significant, as it can lead to ad fraud and creation of a proxy botnet. The affected products are Android-based vehicle head unit firmware developed by DoFun. The blast radius of this threat is moderate to high, as it can affect multiple vehicles and potentially lead to financial losses.

Recommended Actions

To mitigate this threat, security professionals should:

  • Investigate and identify potentially affected vehicles
  • Block suspicious traffic and updates from the vehicle's head unit
  • Implement security measures to prevent supply chain attacks
  • Monitor for and detect potential ad fraud and proxy botnet activity

Sources

The Hacker News