Threat Intelligence

New Android Malware Targets In-Car Entertainment Systems for Ad Fraud and Proxy Networks

The Hacker News · 22 Aug 2026
Key Takeaway If your business uses connected vehicles, smart devices, or IoT equipment, ensure their software updates come only from verified, trusted sources and are monitored for unusual behaviour.

Cybersecurity researchers at Kaspersky have discovered a new malware family specifically designed to infect Android-based vehicle head unit firmware manufactured by DoFun. The malware was identified in June 2026 and represents a growing trend of attackers targeting embedded and connected devices beyond traditional computers and phones.

According to Kaspersky, the malware spreads through the built-in updater feature of the affected devices, delivering a multi-stage downloader onto infected systems. Once installed, the malware's ultimate goal is to enable ad fraud schemes and recruit devices into a proxy botnet, which criminals can use to route malicious traffic and disguise their identity online.

While this particular attack targets vehicle infotainment systems rather than business devices, it highlights a broader risk for small businesses: any internet-connected device with automatic update functionality, from smart displays to fleet vehicles, can become an entry point for attackers if the update mechanism itself is compromised or insufficiently secured. Businesses using connected vehicles or IoT devices as part of their operations should be aware that these systems are increasingly attractive targets for cybercriminals.

Android malware IoT security ad fraud botnet connected vehicles

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.