How the TWCore Exploit Enabled Silent Infection
Security researchers discovered a vulnerability in an analytics application that allowed hackers to inject malware into car head units running Android. The attack, identified by Kaspersky in August 2026, exploited the DoFun brand of infotainment systems through a component called TWCore. Once installed, the malware connects infected vehicles to a concealed proxy network, enabling remote control and data routing without the driver’s knowledge. The campaign highlights growing risks in connected car ecosystems where third-party apps can serve as entry points for cyber threats.
Latest news
Apple unveils new iPhone lineup next week
NordVPN Browser Extension Gets Redesigned Interface and Smarter Search
Ugreen's DXP6800 Pro NAS Benefits From Additional Network Upgrade
Google Gemini Error Strands Climbers on Mount ShastaThe flaw resided in an analytics tool bundled with the infotainment software, which lacked proper validation for external code execution. Attackers used this weakness to push a malicious payload that disguises itself as a system update. After installation, the malware establishes a persistent connection to command-and-control servers, effectively turning the car into a node in a decentralized proxy network. This allows cybercriminals to route traffic through the vehicle’s internet connection, masking their true location and potentially enabling illegal activities such as fraud or data theft. Kaspersky noted that the malware does not disrupt driving functions but focuses on stealthy background operations.
Could This Lead to Larger-Scale Attacks on Connected Vehicles?
The TWCore framework, designed to manage app analytics and updates, failed to verify the authenticity of incoming data packets. By mimicking legitimate update requests, hackers bypassed digital signature checks and injected the malware directly into the system partition. This method avoided triggering standard security alerts because it exploited a trusted internal process rather than relying on user interaction. Once embedded, the malware gained elevated privileges, allowing it to hide its presence and resist removal through normal user actions. Researchers emphasized that the attack required no physical access to the vehicle, making it scalable across regions where DoFun units are deployed.
Security experts warn that this technique could be adapted to target other vehicle brands using similar Android-based architectures. While no evidence suggests the proxy network was used for large-scale disruption, its existence proves that cars can be recruited into cybercriminal infrastructure without detection. The incident underscores the need for stricter code signing, runtime monitoring, and isolated execution environments in automotive software. Manufacturers are urged to audit third-party components and implement over-the-air patching mechanisms capable of responding to such threats swiftly.
What type of data could be exposed through this proxy network? The malware could allow attackers to route malicious traffic, potentially hiding the origin of cyberattacks, but there is no indication that personal vehicle data or driver information was directly stolen in this campaign.
Frequently Asked Questions
Is it possible to remove the malware from affected cars? Yes, the threat can be eliminated through a system update or factory reset, though users may not be aware of infection due to the malware’s stealthy design and lack of noticeable symptoms.
Are other car brands at risk beyond DoFun systems? Any vehicle using Android-based infotainment with insufficient validation in update mechanisms could be vulnerable, though Kaspersky’s findings specifically relate to the DoFun TWCore implementation in this case.
Comments
Leave a comment