“The malware spread through the built-in updaters of Android-based automotive head unit firmware. This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device.”

Attackers compromised the TWCore update mechanism and pushed APKs onto DoFun units without any user action. The payload runs ad fraud and a proxy botnet, so your dashboard is now residential exit traffic for someone else. Head units ship with an OS nobody patches, an update channel nobody audits, and a lifespan measured in decades. There is no recall process for this.