Specialists at Kaspersky have identified the first virus specifically designed to infect multimedia systems in cars that use the Android operating system. This malware was targeted at models utilizing software from the Chinese company DoFun, which is part of Shenzhen Driving Control Technology.
It is important to note that the virus was not tied to any specific car brand; instead, it affected 'universal multimedia centers with Android and customized systems that use the DoFun software infrastructure and theme store,' explained technology specialist Leonardo La Rosa in an interview with Olhar Digital.
This operation was attributed to cybercriminals associated with the BADBOX and MoYu Group networks. According to the specialist, these groups are 'operators specializing in mass infection of vulnerable Android ecosystems—such as inexpensive TV boxes, and now car manufacturers' multimedia centers using solutions from the Chinese company DoFun.'
The developer of this software was notified by the cybersecurity service researchers. According to Kaspersky, the discovered vulnerabilities have been patched, theoretically closing this incident. However, this has paved the way for potentially more serious future incidents.
The virus infected the multimedia centers without the user noticing. Kaspersky reported that it utilized an existing resource within the vehicle's system. As AI specialist Stefano Levorato clarified in an interview with Olhar Digital, 'this does not mean that someone automatically gained access to control, braking, or acceleration of the vehicle.'
In practice, the infected media center became slower and consumed more internet data, which might seem like a minor inconvenience. Nevertheless, La Rosa emphasized: 'The main threat lies in the concept of an 'open door.' '
When malicious software installs a backdoor in the vehicle's central unit, the device begins responding to remote commands. The director warns: 'A criminal may decide to sell access to this connection to other cybercriminals so they can mask digital crimes using your car's IP address.'
Furthermore, more aggressive modules could be introduced in the future, capable of collecting personal data, associated accounts, and the driver's navigation history.
The real danger lies not in the current symptom but in the bridge built for tomorrow's attack.
Levorato, who is a co-founder of the Brazilian Society of Innovation (SBI) and National Director of the Global Innovation Institute (GInI) in Brazil, highlights another aspect: 'We must be very careful not to turn possibility into fact. To our knowledge, there is no evidence that the malware reached critical vehicle systems.'
He notes that there is only potential for evolution within the compromised environment. In Levorato's opinion, to reach systems such as braking, steering, or the powertrain of a modern car, a hacker would still have to overcome other security barriers.
For La Rosa, this case marks a turning point because, according to him, it officially signals the transition of botnets from the realm of computers and smartphones into the field of automotive IoT. He observes: 'Criminals have realized that modern cars have turned into large smartphones on wheels, but they often lack the same maturity in terms of security and update cycles as a flagship mobile phone.'
La Rosa continues, pointing out that 'this is a paradigm shift. Hackers have noticed that there is an ocean of underutilized and poorly protected computing power in garages all over the world.'
The specialist also points out that 'as automakers increasingly integrate infotainment systems with vehicle sensors and controls for convenience, the attack surface is only increasing.'
He concludes: 'The automotive market must learn to treat firmware and software with the same level of security as mechanical engineering.'
La Rosa also emphasizes that this case of a botnet in multimedia centers serves as a kind of 'Proof of Concept' for cybercriminals. It demonstrated that attackers were able to penetrate and utilize light and the internet.
'The real danger in the future is that, once inside, they will start trying to open doors to rooms where locks, geolocation, sensors, and core vehicle systems are located.'
For Levorato, this case 'does not necessarily create a path for similar or worse attacks.' It merely demonstrates that this type of attack exists and can be implemented on a large scale.
The main significance of this episode lies not so much in the damage caused by this specific malware, but in the warning it carries regarding the new technological environment of the automobile.
What to do in the face of this threat? La Rosa advises: 'The first piece of advice is always to keep the car's software up to date and prefer official updates provided by the manufacturer or dealer.'
Another tip from the specialist: 'Absolutely avoid rooting procedures, installing parallel firmwares, or downloading applications from sources other than official stores in an attempt to unlock features in the multimedia center.'
The director also recommended: 'If you use a universal or modified Android infotainment system, avoid connecting your most confidential accounts or conducting financial transactions through it.'
Finally, pay attention to operational signs: if the car screen starts showing unusual freezes, excessive and unexplained internet traffic consumption, or strange behavior when starting the car, contact the brand's technical support to check the system's integrity.
Levorato adds that 'responsibility cannot be entirely shifted to the consumer. There is part of the car system that the owner simply cannot control.'
In his view, fixing firmware vulnerabilities, integrating vehicle systems, security of updates, and threat monitoring depend on automakers and their suppliers.

