Hackers used a trusted system update app on DoFun Android-based car head units to secretly install malware that turns affected devices into proxy botnet nodes and ad-fraud tools. Kaspersky attributes the campaign to the MoYu group, previously linked to BadBox. The malware chain starts with a rogue APK delivered via DoFun's TWCore app, then deploys JarService and later-stage payloads from attacker infrastructure including an MQTT server at cardoor[.]cn.
Why it matters: People and organizations using affected aftermarket Android car head units may have had their devices abused for fraud or as covert internet relay points without realizing it. Owners and fleet operators should check with DoFun for updated software, review device network activity, and treat these units as potentially compromised supply-chain devices.
Eduard Kovacs
2026.08.25
95% relevant
This article adds that Kaspersky believes the malware is the first built specifically for car head units, says attackers exploited the software-update system and compromised the update distribution channel, and links the activity to MoYu Group and the broader BadBox botnet.
2026.08.24
98% relevant
This is the same underlying event: malware on DoFun Android car head units delivered via the legitimate TWCore update app, used to install JarService and turn devices into reverse proxies, with attribution to MoYu Group tied to BadBox.
Bill Toulas
2026.08.22
100% relevant
This article establishes a distinct new event: a documented supply-chain malware campaign targeting DoFun Android car head units through the vendor's legitimate TWCore update mechanism.
← Back to all stories