{
  "id": 3083105,
  "title": "Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet",
  "url": "https://urgent.news/2026/08/24/even-connected-car-head-units-are-being-targeted-by-hackers-now",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-24T18:35:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/even-connected-car-head-units-are-being-targeted-by-hackers-now-experts-warn-in-car-systems-are-at-risk-of-being-hijacked-into-a-botnet"
  },
  "original_language": "en",
  "account": "Hackers have allegedly infiltrated car head units through trusted software updates, potentially turning them into part of a botnet, according to security firm Kaspersky. This marks the first known instance of malware specifically designed for vehicle head units, which are increasingly being targeted in Android malware campaigns. The attack vector originates from TWCore, an app typically responsible for software updates and analytics, which attackers hijacked using a dropper called JarService. Once installed, the malware operated silently in the background without displaying any visible interface. It was able to collect device information such as display resolution, model, Wi-Fi network identifier, and MAC address, and execute remote commands for displaying ads and fraudulently collecting data. The malware is believed to be linked to the MoYu Group, a threat actor associated with the BadBox botnet, which previously spread through legitimate update mechanisms. The attack highlights the growing vulnerability of connected vehicle systems, which often rely on Android-based head units that lack robust security measures. Despite the lack of sensitive personal data stored directly on these devices, their constant connectivity and integration with navigation services make them an attractive target for cybercriminals. Kaspersky has notified the vendor about this issue, which they claim has been resolved across most affected devices. However, the full extent of this particular campaign and whether other head unit manufacturers are similarly exposed remain unclear.",
  "summary": "Kaspersky discovers Android malware targeting car head units through compromised updates.",
  "key_points": [
    "Hackers infiltrated car head units via trusted software updates.",
    "TWCore app hijacked by dropper called JarService.",
    "Malware linked to MoYu Group's BadBox botnet."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}