Back to The Local Vocal
The Local VocalMedium
Email
Medium risk 3rd Party Advisory 25 August 2026
RegionNew Zealand

Dodgy car updater could rope your gear in

Malware is being pushed through built-in updaters on some Android-based vehicle head units, turning affected systems into ad fraud and proxy botnet nodes.

This is not an email campaign. It is an Android malware advisory affecting some vehicle head units built on DoFun firmware, where the device’s own built-in updater can deliver a malicious multi-stage downloader instead of a legitimate update. If you run vehicles, fleet systems, or aftermarket infotainment units that rely on Android-based head units, you need to treat update activity on those devices as potentially risky until you confirm what firmware is in use.

What gives this away is the delivery path. Researchers found the malware spreading through the updater already trusted by the device, which means the compromise can look like a normal firmware or system update rather than an obvious fake app or suspicious link. In plain language, the system you would normally rely on to keep the unit safe may be the thing being utilised to install the threat, so trust in the update channel itself needs to be checked.

The attacker is after persistent access they can monetise. The malware is designed to pull down more components, then utilise the head unit for ad fraud and as part of a proxy botnet. If one of your devices is affected, your network connection and equipment could be quietly misused, performance could degrade, and the compromised unit could become a stepping stone for broader abuse inside your environment.

This is likely relevant anywhere Android-based in-vehicle systems are used in business operations, especially fleets, workshops, logistics, and transport providers. It may keep appearing because the updater mechanism is built into the platform, so any organisation with the affected firmware line should assume the risk is shared across similar devices until the vendor and your technology provider verify otherwise.

Source: The Hacker News — https://thehackernews.com/2026/08/android-car-malware-spreads-through.html

Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Check: Review whether your business uses Android-based vehicle head units, especially in fleet, logistics, field service, or workshop environments.
  • Check: Confirm whether any affected devices run DoFun firmware, and review their patch status, update source, and network behaviour with your IT provider or vendor.
  • Do not: Ignore vendor or agency advisories on embedded Android platforms. Acting within the recommended timeframe reduces exposure significantly.
  • Report: If the described threat is found, notify your IT provider immediately. If active exploitation is suspected, report it to NCSC NZ at report.ncsc.govt.nz.
  • Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.