Even if the driver is vigilant about cyber risks—avoiding suspicious links, not connecting unknown flash drives, and not using pirated applications—their car's multimedia center can become part of an online criminal network.
This was reported by an analysis from Kaspersky concerning malware campaigns specifically designed to infect Android-based multimedia systems.
According to researchers, the attack utilized the device's own update mechanism, which is intended to ensure system security. After installation, the malicious program ran in the background, showing no icons or warnings on the screen, thus paving the way for subsequent loading of other components.
The analysis revealed functions that allowed collecting technical device data, such as model, screen resolution, connected Wi-Fi network, and MAC address. Furthermore, the code engaged in advertising fraud and, more importantly, turned the central unit into a proxy server through which traffic from third-party users passed, integrating the hardware into a botnet—a remotely controlled network of devices.
The activity was highly confidently attributed to the criminal group MoYu, associated with the BadBox botnet, which had previously been involved in attacks on other Android devices.
Fortunately, there is no evidence that the attackers gained control over the vehicle's steering wheel, brakes, or accelerator; the target was specifically the multimedia system and its internet connection, not the critical vehicle systems.
Kaspersky also did not disclose a list of affected vehicles, and having Android multimedia or using Android Auto does not inherently mean vulnerability. The infected centers used software from the Chinese company DoFun, which supplies solutions to both automakers and aftermarket installers.
This second segment is very common in Brazil, where replacing the factory radio with a universal Android multimedia unit has become commonplace, often occurring in accessory stores without a guarantee that the software developer will continue to release fixes. Some of these devices have their own connectivity, including a SIM card, which increases the risk.
DoFun was notified and stated that it has eliminated the discovered vulnerability, making system updates the primary defense measure. It is also recommended to install software only from official sources, avoid APK files and alternative stores, check whether the manufacturer provides security updates, and contact technical support if the central unit starts displaying unexpected advertisements, freezing without reason, or consuming an unusually large amount of data.


