Researchers report a supply-chain style attack that infects Android-based vehicle head units using a legitimate device-update application. The malware is reported to target firmware for car head units and then enlist compromised devices in criminal infrastructure.

Kaspersky says it identified the threat in June 2026 and traced it to a new malware family designed around a multi-stage download process. That process is described as supporting both ad fraud and the creation of a proxy botnet, in which infected devices relay network traffic as part of the attackers’ operations. Other reporting similarly frames the campaign as using built-in update mechanisms to reach targets rather than requiring direct user action.

While the outlets agree on the use of an update pathway and the malware’s end goals, they emphasize different operational details: one highlights the broader proxy botnet/ad-fraud outcome, while another focuses on the specific connection to vehicle head unit firmware associated with DoFun and the timing of Kaspersky’s discovery. No public information in the provided excerpts identifies specific affected models or the scale of the compromise.