Tech · Breaking
🇹🇷 TürkiyeHow Does a Hacked Car Reveal This?

A routine update on your car's screen may not be as innocent as it seems. A new attack method, which can occur without the driver making any mistake, has brought the hidden risk in vehicles back into the spotlight. How does a hacked car reveal this?
The details are giving car owners serious pause. As cars have become digital platforms connected to the internet, mobile apps, and cloud systems, cybercriminals' targets have expanded. A new attack campaign detected by Kaspersky revealed that Android-based in-car multimedia systems can be directly targeted with malware.
Notably, the attack can be carried out through the system's own software update mechanism, without users needing to download any suspicious files. In the attack, the communication channel of a legitimate update application used in vehicle multimedia systems is abused to load malware onto the device. The multi-stage attack chain can carry out activities ranging from ad fraud to data collection and downloading additional malicious modules.
Even more striking is that attackers do not need the driver to click an email, install a suspicious app, or make any mistake. 'This is the first malware case. IT expert Osman Demircan said, "It wouldn't be right to say cars are being hacked for the first time here.
We've seen vulnerabilities in cars' Bluetooth, Wi-Fi, keyless entry, telematics systems, mobile apps, and multimedia units for years." He added, "What's new and important is that cybercriminals have now started to see the car itself as a digital target. Demircan highlighted that cybersecurity researchers documented this as an attack distributed in a real environment with an infection chain specifically prepared for vehicle multimedia units, calling it the first malware case." He noted that while attacks once required physical proximity, OBD port devices, Bluetooth range, or USB malware, today's cars operate as a computer network connected to the cloud, manufacturer servers, mobile apps, AP Is, SIM cards, Wi-Fi, and OTA update systems, meaning attackers may not even need to be near the vehicle. Upstream Security's 2026 report examines 494 publicly disclosed automotive and smart mobility cyber incidents in 2025. It states that 92 percent of incidents were carried out remotely, 86 percent required no physical proximity to vehicles or systems, and telematics/cloud systems were among attack vectors in 67 percent of incidents.
The expert said the recent attack chain is a good example, explaining that the legitimate system app 'TW Core' in the vehicle normally receives information from the manufacturer's server about which app to install or update. Attackers abused this distribution channel to introduce the JarService loader and then several other malicious modules, meaning the driver doesn't need to click an email, install a pirated APK, or even make any mistake—just updating or having the update done automatically is enough. How can a driver tell if their multimedia system has been attacked?
Demircan listed symptoms: the multimedia screen slowing down for no reason, frequent restarts, unexpected ads, the car's SIM card or hotspot connection consuming much more internet than normal, apps or services appearing that weren't there before, the system overheating, unusual data traffic while parked, or multimedia settings changing on their own. He emphasized that uncontrolled and excessive data consumption is one of the most telling signs, as the car's internet connection may be used to route other people's traffic without the owner's knowledge. However, he cautioned that it's not really possible to say users can definitely tell, as well-designed malware works to stay invisible, making remote security monitoring, log analysis, integrity checks, and service-level malware detection by the car or multimedia manufacturer far more important.
Source: Hürriyet Gündem, CNN Türk Türkiye
- Türkiye
- Technology
- How
- Hacked Car
- Car Reveal
Most read in this category
Loading article…