Malware Is Turning Your Car's Touchscreen Into a Hacker's Tool
According to The Record, researchers at Kaspersky have uncovered what they believe is the first documented case of malware purpose-built to infect car head units — the Android-powered touchscreens that handle navigation, music and Bluetooth in modern vehicles.
The infected devices were made by DoFun, a Chinese automotive software and hardware provider. Attackers compromised a legitimate app called TWCore, which is pre-installed on DoFun devices to handle analytics and software updates. Because TWCore has permission to download and install new apps, attackers used it to silently push a malicious app called JarService onto vehicles — no link to click, no website to visit, nothing for the driver to do.
JarService has no visible interface. Drivers would have no reason to suspect anything was wrong. Once installed, it downloads additional malicious modules. Some display ads and generate fake clicks. Others do something more unsettling: they turn the car's internet connection into a reverse proxy, routing other people's traffic through the vehicle to disguise where that activity originated. Think of it like someone rerouting their calls through your phone number without asking.
Kaspersky attributes the campaign with high confidence to MoYu Group, a threat actor connected to the BadBox malware operation — which has previously shipped malware on Android phones, tablets and streaming boxes before they reached consumers. German authorities disrupted the original BadBox botnet in December 2024, but new variants keep appearing.
If your car runs a DoFun head unit, check the manufacturer's website for a firmware update. More broadly, treat your car's internet connection like any other connected device — it is one.
Sources

