Kaspersky says it found Android malware aimed at DoFun in-vehicle infotainment systems. The campaign hits Android-based DoFun head units and similar dash systems, pulling ad fraud and proxy-botnet activity into the dashboard itself.
Per Kaspersky, the malicious code shipped alongside legitimate DoFun software, which points to a supply-chain or packaging compromise that most users, installers, and resellers wouldn’t catch. It runs without any visible interface and quietly collects the device model, screen resolution, and Wi-Fi network ID. Not passwords or banking details, but enough to profile infected units, manage them, and make money from them.
It also matches the broader direction automotive security has been heading. Public automotive cyber incidents reached 494 in 2025. Ransomware made up 44% of them. Back in 2022, 97% of logged attacks were remote. VicOne says more than 77% of automotive vulnerabilities are in onboard systems, and IVI security spending is projected to climb from $2.4 billion in 2025 to $7.56 billion by 2034.
If you use a DoFun head unit, or depend on third-party or unofficial updates, don’t brush this off.