THE article discusses a new Android malware targeting car head unit systems, allowing threat actors to exploit legitimate update functions to spread infections. Named JarService, this malware was discovered by Kaspersky researchers who noted it lacks a user interface and operates as a multistage downloader. The malware takes advantage of vulnerabilities in the firmware update application (TWCore) of DoFun's infotainment systems.
This marks the first documented case of malware infecting car head units, which primarily handle entertainment and information systems rather than critical vehicle functions. The MoYu Group, linked to the notorious BadBox botnet, is believed to be responsible for this malware, aiming to create a proxy botnet for click fraud. Kaspersky has reported the issue to DoFun, which has since addressed the vulnerabilities.