New Android Malware Targets In-Car Entertainment Systems for Ad Fraud and Proxy Networks
Cybersecurity researchers at Kaspersky have discovered a new malware family specifically designed to infect Android-based vehicle head unit firmware manufactured by DoFun. The malware was identified in June 2026 and represents a growing trend of attackers targeting embedded and connected devices beyond traditional computers and phones.
According to Kaspersky, the malware spreads through the built-in updater feature of the affected devices, delivering a multi-stage downloader onto infected systems. Once installed, the malware's ultimate goal is to enable ad fraud schemes and recruit devices into a proxy botnet, which criminals can use to route malicious traffic and disguise their identity online.
While this particular attack targets vehicle infotainment systems rather than business devices, it highlights a broader risk for small businesses: any internet-connected device with automatic update functionality, from smart displays to fleet vehicles, can become an entry point for attackers if the update mechanism itself is compromised or insufficiently secured. Businesses using connected vehicles or IoT devices as part of their operations should be aware that these systems are increasingly attractive targets for cybercriminals.