← Home
CYBERSECURITY

Android car infotainment systems compromised by malware turning vehicles into proxy nodes

August 28, 2026 Hannah Osei

How the TWCore Exploit Enabled Silent Infection

Security researchers discovered a vulnerability in an analytics application that allowed hackers to inject malware into car head units running Android. The attack, identified by Kaspersky in August 2026, exploited the DoFun brand of infotainment systems through a component called TWCore. Once installed, the malware connects infected vehicles to a concealed proxy network, enabling remote control and data routing without the driver’s knowledge. The campaign highlights growing risks in connected car ecosystems where third-party apps can serve as entry points for cyber threats.

The flaw resided in an analytics tool bundled with the infotainment software, which lacked proper validation for external code execution. Attackers used this weakness to push a malicious payload that disguises itself as a system update. After installation, the malware establishes a persistent connection to command-and-control servers, effectively turning the car into a node in a decentralized proxy network. This allows cybercriminals to route traffic through the vehicle’s internet connection, masking their true location and potentially enabling illegal activities such as fraud or data theft. Kaspersky noted that the malware does not disrupt driving functions but focuses on stealthy background operations.

Could This Lead to Larger-Scale Attacks on Connected Vehicles?

The TWCore framework, designed to manage app analytics and updates, failed to verify the authenticity of incoming data packets. By mimicking legitimate update requests, hackers bypassed digital signature checks and injected the malware directly into the system partition. This method avoided triggering standard security alerts because it exploited a trusted internal process rather than relying on user interaction. Once embedded, the malware gained elevated privileges, allowing it to hide its presence and resist removal through normal user actions. Researchers emphasized that the attack required no physical access to the vehicle, making it scalable across regions where DoFun units are deployed.

Security experts warn that this technique could be adapted to target other vehicle brands using similar Android-based architectures. While no evidence suggests the proxy network was used for large-scale disruption, its existence proves that cars can be recruited into cybercriminal infrastructure without detection. The incident underscores the need for stricter code signing, runtime monitoring, and isolated execution environments in automotive software. Manufacturers are urged to audit third-party components and implement over-the-air patching mechanisms capable of responding to such threats swiftly.

What type of data could be exposed through this proxy network? The malware could allow attackers to route malicious traffic, potentially hiding the origin of cyberattacks, but there is no indication that personal vehicle data or driver information was directly stolen in this campaign.

Frequently Asked Questions

Is it possible to remove the malware from affected cars? Yes, the threat can be eliminated through a system update or factory reset, though users may not be aware of infection due to the malware’s stealthy design and lack of noticeable symptoms.

Are other car brands at risk beyond DoFun systems? Any vehicle using Android-based infotainment with insufficient validation in update mechanisms could be vulnerable, though Kaspersky’s findings specifically relate to the DoFun TWCore implementation in this case.

Read full article on Tech Site News →