Skip to content
Securelist·

🚨New Android Malware Infects Car Head Units for Ad Fraud

Your car's head unit could be a new ad fraud vector

TL;DR

A newly discovered malware targets Android-based automotive head units, spreading through built-in updaters and enabling ad fraud. Detected by Kaspersky, this is the first of its kind to exploit car systems.

Kaspersky has uncovered a new strain of Android malware targeting automotive head units for ad fraud purposes. The malware installs itself without user interaction via TWCore, an application responsible for updates. This marks the first documented case of such attacks on car devices. Developers and security teams must now consider these systems as potential entry points for malicious activities, especially in environments where physical access is limited or impossible to control.

New Android Malware Infects Car Head Units for Ad Fraud — Securelist

Key Points

1

Malware discovered June 2026, first documented case of car head unit infection.

2

TWCore sends MQTT messages to download APK files, installing apps not originally present on the device.

3

JarService decrypts data stored in its code for further malware loading.

4

Stage 2 malware sends implant information to attacker's server via POST requests every 90 minutes.

5

Seven distinct stage 3 payload variants obtained with different version numbers.

Why It Matters

If you're working on automotive software or managing fleets, this is a critical security flaw. The malware exploits TWCore for updates and can install itself without user interaction. Head units are now vulnerable to ad fraud and botnet creation.

androidmalwareautomotivead-fraudkaspersky

Frequently Asked Questions

Why does this matter?

If you're working on automotive software or managing fleets, this is a critical security flaw. The malware exploits TWCore for updates and can install itself without user interaction. Head units are now vulnerable to ad fraud and botnet creation.

What happened?

A newly discovered malware targets Android-based automotive head units, spreading through built-in updaters and enabling ad fraud. Detected by Kaspersky, this is the first of its kind to exploit car systems.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,315 builders reading daily.

Also get