Kaspersky Unveils DoFun Infotainment Malware Flaw
In August 2026, Kaspersky Lab disclosed a novel malware campaign targeting Android-based in-vehicle infotainment systems manufactured by DoFun. The vulnerability exploits a pre-installed system service called TWCore, which is embedded by the automaker as part of the vehicle's native software stack. Through this service, attackers can remotely install a malicious module named JarService, which then acts as a gateway for delivering additional payloads, including a downloader and the zhima trojan, enabling full control over the head unit.
Once compromised, the malware grants threat actors the ability to manipulate core vehicle functions through the infotainment interface, harvest sensitive user data such as contacts, locations, and credentials, and even enlist infected units into a distributed botnet for further malicious activities. According to Kaspersky's telemetry, the campaign has affected more than 30 million vehicles worldwide, spanning multiple regions and automaker brands that rely on DoFun's infotainment solutions.
The attack vector requires the vehicle's infotainment system to be connected to the internet at the time of exploitation. This condition is commonly met in modern cars featuring always-on connectivity, over-the-air updates, or mobile hotspot functionality. However, vehicles operating in offline or isolated environments remain unaffected, providing a limited but meaningful mitigation for some users.
Kaspersky researchers noted that the malware's design demonstrates a high degree of sophistication, with modular architecture allowing remote operators to update or replace the payload on the fly. The initial infiltration likely occurred through a compromised supply chain or via malicious updates pushed to the TWCore service, although the exact delivery mechanism remains under active investigation.
DoFun has since released a security patch addressing the vulnerability, which is distributed through official service channels and, where supported, via over-the-air system updates. Vehicle owners are strongly advised to install the latest firmware version immediately or contact their dealer or manufacturer's support team for guidance on securing their infotainment systems. Users are also encouraged to avoid connecting their vehicle's system to untrusted Wi-Fi networks and to disable unnecessary remote access features until the patch is applied.
This disclosure highlights the growing security risks associated with increasingly connected automotive ecosystems, where a single compromised infotainment component can expose both personal data and critical vehicle functions. Kaspersky's findings serve as a reminder for automakers and suppliers to adopt stricter security validation processes and for consumers to remain vigilant about updating their vehicle software as soon as patches become available.
