DoFun Android car head units were infected through a legitimate update app and turned into proxy botnet nodes

Hackers used a trusted system update app on DoFun Android-based car head units to secretly install malware that turns affected devices into proxy botnet nodes and ad-fraud tools. Kaspersky attributes the campaign to the MoYu group, previously linked to BadBox. The malware chain starts with a rogue APK delivered via DoFun's TWCore app, then deploys JarService and later-stage payloads from attacker infrastructure including an MQTT server at cardoor[.]cn.
Why it matters: People and organizations using affected aftermarket Android car head units may have had their devices abused for fraud or as covert internet relay points without realizing it. Owners and fleet operators should check with DoFun for updated software, review device network activity, and treat these units as potentially compromised supply-chain devices.

Sources

First Malware Built Specifically for Car Head Units Fuels Botnet
Eduard Kovacs 2026.08.25 95% relevant
This article adds that Kaspersky believes the malware is the first built specifically for car head units, says attackers exploited the software-update system and compromised the update distribution channel, and links the activity to MoYu Group and the broader BadBox botnet.
Hackers infecting Android car systems to build proxy botnet
2026.08.24 98% relevant
This is the same underlying event: malware on DoFun Android car head units delivered via the legitimate TWCore update app, used to install JarService and turn devices into reverse proxies, with attribution to MoYu Group tied to BadBox.
Hackers infect Android car head units with proxy botnet malware
Bill Toulas 2026.08.22 100% relevant
This article establishes a distinct new event: a documented supply-chain malware campaign targeting DoFun Android car head units through the vendor's legitimate TWCore update mechanism.
← Back to all stories