Kaspersky researchers uncovered a sophisticated malware family targeting Android-based vehicle infotainment systems manufactured by DoFun, distributing malicious code through legitimate-looking firmware update channels to conduct ad fraud and recruit compromised devices into a proxy botnet.

The threat emerged in June 2026 when Kaspersky's security team identified suspicious activity within DoFun's built-in updater mechanism. The malware functions as a multi-stage downloader, meaning infected vehicles first receive a lightweight payload that subsequently pulls additional malicious components onto the system. This architecture allows attackers to modify their attack approach after initial compromise, deploying either ad fraud modules or botnet proxy software depending on attacker objectives.

The attack vector exploits user trust in manufacturer-provided updates. Vehicle owners receive firmware update notifications that appear legitimate but contain embedded malicious code. Since these updates come through trusted channels pre-installed on the hardware, detection and user skepticism remain low. This represents a particularly dangerous threat model because vehicle infotainment systems typically run with elevated privileges and persistent network connectivity, making them ideal infrastructure for large-scale fraud operations.

Ad fraud components generate revenue by simulating legitimate user interactions with advertisements, inflating click counts and impression metrics for malicious publishers or competitors. This particular scheme typically targets mobile advertising networks and generates revenue through pay-per-click mechanisms. Proxy botnet functionality converts infected vehicles into exit nodes for anonymous traffic routing, allowing threat actors to mask their digital footprints while conducting other cybercrimes or selling proxy access to other threat groups.

DoFun's Android-based head units appear in numerous aftermarket car infotainment systems and OEM integrated solutions, particularly in budget to mid-range vehicles across Asia and emerging markets. The exact number of affected devices remains unclear, though the distribution through legitimate updaters suggests potential for rapid infection across multiple vehicles simultaneously.

The incident highlights critical vulnerabilities in automotive software supply chains. Unlike smartphones with centralized app store security reviews, vehicle firmware updates often bypass equivalent security screening. Manufacturers prioritize update delivery speed over rigorous threat analysis. Additionally, many vehicle owners disable security notifications to avoid update interruptions during daily driving.

Kaspersky has not publicly disclosed whether DoFun patched the vulnerability or issued corrected firmware. The company typically coordinates with manufacturers before full public disclosure, though details may remain limited to protect operational security.

This discovery intersects with broader automotive cybersecurity concerns surrounding connected vehicles. Modern cars increasingly function as mobile computing platforms with network-connected systems managing everything from navigation to brake control. Malware capable of persisting across firmware updates can remain operational indefinitely, potentially laying groundwork for future attacks targeting vehicle safety systems rather than just ad fraud infrastructure.

Vehicle owners running DoFun-based infotainment systems should verify firmware versions against official manufacturer advisories and avoid accepting unexpected update prompts from untrusted sources. Organizations managing vehicle fleets should audit their infotainment system vendors and implement network segmentation isolating vehicle systems from corporate networks to prevent botnet pivot attacks.