Your Car Has Fleas. Your Car Has Actual Fleas.
I have spent thirty-one years warning anyone who would listen that putting a computer in a vehicle was a catastrophic mistake. My 1994 Volvo runs on stubbornness and mechanical principle. It has never once attempted to join a botnet. I rest my case.
Kaspersky researchers, bless their modern hearts, flagged a new parasite family in June 2026 targeting Android-based vehicle head units manufactured by DoFun. The fleas embed themselves through the vehicle's own built-in updater mechanism, which is precisely the kind of irony that keeps me awake at night. The update system, designed to protect the flock, is the hole in the fence. The wolves did not even need to pick a lock. Someone left the barn door labeled "PLEASE USE THIS."
The end objective is a multi-stage downloader enabling ad fraud and proxy botnet enrollment. Your car is now a small, mobile, climate-controlled criminal enterprise. It is commuting to work and committing financial crimes simultaneously. I hope the fuel efficiency is worth it.
The Shepherds who greenlit "let's put Android in the dashboard" presumably received a very nice PowerPoint presentation and a catered lunch before signing off. Nobody asked the Paranoia Consultant. Nobody ever asks the Paranoia Consultant.
In the Old Days, your car's most sophisticated technology was a cassette deck. It could not be compromised remotely. The worst thing that happened was the tape getting eaten, and that was a mechanical problem solved with a pencil. I understood pencils. I trusted pencils.
The Sky Pasture integration, the always-on connectivity, the assumption that convenience outweighs catastrophic attack surface expansion. This is what happens. This is always what happens.
Remediation
The Shepherds will not like this list. That is how I know it is correct.
Immediately: - Verify your head unit firmware version and cross-reference against Kaspersky's published indicators of compromise. Yes, manually. Get up. - Disable automatic updates on affected DoFun units until a clean firmware build is confirmed and independently verified. Ironic, I know. Do it anyway. - Audit any device using your vehicle's hotspot or network connection. The proxy botnet needs to route through something.
Structurally: - Network-segment your vehicle's head unit from anything that matters. Treat it like a suspicious stranger at the fence line. - Demand your automotive vendor provide a signed, verified update chain. If they cannot explain how their updater validates integrity, that is your answer. - Consider, just briefly, whether your car needs to be online at all times. Consider it seriously.
My 1994 Volvo remains available for consultation. It charges a flat rate of silence and zero ad impressions.
Original Report: https://thehackernews.com/2026/08/android-car-malware-spreads-through.html