Cyber Risks Are Everywhere. Even in Places You'd Never Think to Look.

Cyber Risks Are Everywhere. Even in Places You'd Never Think to Look.

Here's a story worth five minutes of your attention. Not because it's an emergency, but because of what it represents.

Security researchers at Kaspersky recently uncovered a malware campaign targeting certain Android-based automotive infotainment systems. What's notable isn't just the target. It's how the malware was delivered. According to Kaspersky's findings, attackers leveraged a legitimate software update mechanism that was already trusted by the device. No phishing email. No suspicious download. No employee clicking the wrong link. The malware arrived through the same channel the device was designed to trust. [kaspersky.com], [bleepingcomputer.com]

Before anyone starts worrying about the vehicles in their parking lot, let's add some important context. There is no indication that this particular threat is widespread in our region, and reporting has not identified a specific concentration of affected vehicles in New England. The real value of this story isn't the immediate threat. It's the lesson behind it. [kaspersky.com], [kaspersky.com]

What Happened?

The affected systems were Android-based head units powered by technology from DoFun, a Chinese provider of automotive software and hardware. Researchers found that a legitimate application called TWCore, which normally handles analytics and software updates, was used to deliver malicious software through the device's existing update process. [kaspersky.com], [bleepingcomputer.com]

Once installed, the malware operated quietly in the background and could download additional malicious components from attacker-controlled infrastructure. Researchers found that infected devices were primarily being used for two purposes:

Kaspersky attributed the campaign to the MoYu Group, a threat actor associated with the broader BADBOX malware ecosystem. DoFun has stated that the issue has since been addressed. [kaspersky.com], [bleepingcomputer.com]

Importantly, researchers reported that the malware did not affect vehicle safety systems or driving controls. The activity was limited to the infotainment environment and its network connectivity. [bleepingcomputer.com], [kaspersky.com]

Why We Think This Matters

The interesting part of this story isn't that it happened in a car.
It's that nobody had to do anything wrong.

Most of us have heard the standard cybersecurity advice by now: don't click strange links, don't open unexpected attachments, and don't download software you don't trust. That's still good advice. The problem is that not every cyber incident starts with somebody making a bad decision.

In this case, according to the research, the malware came through a legitimate update process that the device already trusted. [kaspersky.com], [kaspersky.com]

That's a reminder that cybersecurity isn't just about user behavior anymore.

Modern businesses depend on dozens, sometimes hundreds, of connected devices that most people never think of as computers. Smart TVs. Security cameras. Digital signs. Printers. Access control systems. Point-of-sale equipment. Building controls. Even vehicles.
Every one of those devices connects to a network. Many update automatically. And most receive far less attention than laptops and servers.

The reality is that cybercriminals tend to look for the things nobody is paying attention to. The device that causes tomorrow's problem probably isn't the one making headlines today.
 

Why Dealerships Should Pay Attention

Dealerships are a perfect example of how much technology has changed over the last decade.

A modern dealership isn't just running a DMS and a few office workstations anymore. Walk through the average showroom, service drive, or back office and you'll find:

  • Guest Wi-Fi networks

  • Service lane tablets

  • Digital signage and displays

  • Security cameras

  • Access control systems

  • Payment terminals

  • Network-connected printers

  • Diagnostic equipment

  • Service kiosks

  • Connected vehicles and loaner fleets

Many of these systems come from different vendors. Some are installed by contractors. Others get connected because they're needed for operations and nobody thinks of them as part of the IT environment.

That's completely understandable.

But from a cybersecurity perspective, if a device touches your network, it becomes part of your environment whether IT purchased it or not.

One of the most common things we discover when onboarding new clients isn't outdated technology. It's technology that nobody realized needed to be managed in the first place.

What We're Asking Our Clients To Do

This isn't one of those articles where we're going to tell everyone to panic.

In fact, it's the opposite.

The biggest takeaway from this story is simply awareness.

Tell Us Before Something New Goes Online
Whether it's a smart TV, service kiosk, digital display, fleet vehicle, or vendor-installed system, we'd rather know about it before it connects to your network than after something goes wrong.

Don't Assume Factory-Installed Means Secure
Most manufacturers work hard to build reliable products, but "it came that way" isn't the same thing as "it's been evaluated from a security standpoint."

Keep Your Inventory Current
Most organizations do a good job tracking laptops and servers. Far fewer maintain an accurate inventory of everything connected to their network. If it's been a while since you've reviewed what's connected, it's worth taking another look.

Ask Vendors How Updates Are Managed
Before purchasing connected technology, ask a simple question:

How does this device receive updates, and who controls that process?

If a vendor struggles to answer that clearly, that's useful information before deployment.

Report Small Issues Early
Unusual network activity, unfamiliar devices, unexplained bandwidth usage, or systems behaving differently than normal might not be serious. But they're always worth mentioning.
We'd much rather investigate a false alarm than discover a problem months later.

A Few Questions Worth Asking

This isn't an urgent threat that requires immediate action. It's a reminder that cybersecurity works best when it's proactive, not reactive.

The organizations that manage risk most effectively aren't the ones scrambling after a headline. They're the ones that already understand what's connected to their environment, who owns it, and how it's maintained.

Ask yourself:

  • Have we identified every device connected to our network or the internet?

  • Do we know who is responsible for managing each of those devices?

  • Do we know how software and security updates are delivered to them?

  • Which systems update automatically, and which require manual intervention?

  • Can we quickly determine which devices are fully patched and which are behind?

  • Do we receive reports or visibility into the patching and security status of those devices?

  • If a vulnerability were disclosed tomorrow, would we know where that technology exists in our environment?

If you're not confident in those answers, you're not alone.
Most businesses are very good at tracking laptops and servers. Far fewer have a complete picture of the growing number of connected devices operating throughout their organization.

Cybersecurity isn't about eliminating every risk overnight. That's rarely practical. It's about understanding your risks, prioritizing them appropriately, and reducing them over time based on operational needs and budget.

The first step is visibility. You can't manage, patch, monitor, or protect a device if you don't know it's there.

The Bottom Line

A vehicle infotainment system probably isn't the first thing that comes to mind when you think about cybersecurity.

That's exactly why this story got our attention.

The specific malware campaign uncovered by Kaspersky may never affect your dealership or business directly. But it highlights something we've been talking about for years: the definition of an endpoint keeps expanding, and cyber risk keeps finding new and unexpected places to live. [kaspersky.com], [bleepingcomputer.com]

This isn't a reason for panic. It's a reason for planning.

Security cannot be an afterthought, and it can't be purely reactive. The most resilient organizations understand their technology, know where their risks exist, and work methodically to reduce those risks over time.

At OWL, that's the conversation we want to have with our clients.

Because we can't help protect a device if nobody knows it's there. And we can't help manage a risk that hasn't been identified yet.
If it's been a while since you've reviewed what's connected to your network, who manages those systems, and how they're being updated, let's have that conversation.

We'd be happy to help you build a clearer picture of your environment and identify opportunities to reduce risk over time.

Sources

  • Kaspersky,"Kaspersky Discovers a Malware Campaign Targeting Car Head Units" (August 21, 2026) [kaspersky.com]

  • Kaspersky Daily,"Botnet on the Road: The First Trojan for Car Head Units" (August 21, 2026) [kaspersky.com]

  • BleepingComputer,"Hackers Infect Android Car Head Units with Proxy Botnet Malware" (August 22, 2026) [bleepingcomputer.com]

Strategic Solutions for Dealership Growth

Strategic Solutions for Dealership Growth

Whether it’s IT services, professional consulting, or operational strategies, OWL Automotive Consulting is here to deliver results.

Let's Connect