If you bought a budget aftermarket Android touchscreen for your car, your dashboard might be secretly working a side hustle for international cybercriminals.Cybersecurity researchers at Kaspersky recently uncovered a completely novel strain of Android malware specifically designed to target and hijack vehicle head units. Instead of messing with your brakes or steering, these hackers are focused on your wallet and your Wi-Fi, turning ordinary infotainment screens into active nodes in a massive proxy botnet and click-fraud scheme.The "DoFun" TrojanBefore you rip the factory stereo out of your dashboard, take a breath. The researchers clarified that this infection does not affect standard Android Auto, which functions merely as a screen mirroring protocol for your smartphone.AdvertisementAdvertisementInstead, the malware specifically hunts down aftermarket Android head units running software built by a Chinese tech company called DoFun.To pull off the digital heist, the threat actors—traced back to the notorious cybercrime syndicate behind the "BadBox" botnet—don't even have to break down the digital front door. They simply exploit TWCore, a completely legitimate system app that handles routine software updates for DoFun units.Honda Infotainment Screen with connected apps.Honda Infotainment Screen | HondaOnce the attackers hijack the update tool, they drop a stealthy background service called JarService onto the car's computer. With no user interface to tip off the driver, JarService quietly decrypts a payload and launches a malicious downloader.AdvertisementAdvertisementWith the door wide open, the hackers have total control over the infotainment unit. They can execute additional malicious code, force the screen to serve fraudulent ads, and use the car's internet connection as a proxy server to route shady web traffic.While your car might still play your favorite Spotify playlist just fine, it could simultaneously be generating fraudulent ad revenue for a cybercrime syndicate halfway across the world.