Malware Discovered in Android-Automotive Head Unit Firmware

Malware Discovered in Android-Automotive Head Unit Firmware

A concerning new form of malware has been detected within the firmware of Android-based automotive head units, according to recent reports by Kaspersky. This malware, which was discovered during routine monitoring of Android threats in June 2026, installs without a user interface and bypasses user detection, sparking significant security concerns for connected vehicles.

The malware specifically targets head units that blend multimedia functions with vehicle control. These systems can be pre-installed by manufacturers or purchased as aftermarket upgrades. Head units running on Android offer manufacturers ease of customization but also present vulnerabilities, making them targets for malicious software, reports Hacker News.

The discovery illustrates a broader issue in the automotive industry concerning software security. As vehicles become increasingly connected, the potential for breaches increases significantly. A key attack scenario involves using malware to convert these head units into parts of a botnet, echoing trends seen in Internet of Things (IoT) device attacks.

Kaspersky identified that the malware was spread through the firmware of DoFun head units. The process included exploiting a legitimate system application, TWCore, which manages software updates and analytics. Using this system, hackers were able to manipulate firmware updates to install malicious software, as documented by Securelist.

TWCore updates use a message broker to send information about required APK installations. The system's vulnerabilities included a mechanism that allowed unauthorized installations, a flaw that the malware exploited to deploy its code onto the head unit devices without detection.

An update from the vendor indicated that the security issues were addressed after Kaspersky's notification. However, this incident highlights the persistent challenges in securing software components of smart car systems, particularly those leveraging open-source platforms like Android.

The malware, dubbed the JarService dropper, comes without any user interface and uses XOR encryption to conceal its actions. Once installed, it can execute additional stages of malicious operations, posing severe risks to users and automotive manufacturers.

As car technology continues to advance, manufacturers may need to implement stricter security protocols and re-evaluate their reliance on widely-used platforms like Android. The stakes are high, with vehicle safety and user data privacy at risk.

This situation demonstrates an urgent need for more robust cybersecurity measures in automotive technology. Ensuring firmware integrity and securing update channels could be pivotal in preventing future breaches of this nature.

More from Issue No.29