ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

Android car malware used built-in updaters

Kaspersky said a malware family targeted DoFun Android vehicle head units by abusing their update process, with the activity attributed to MoYu Group and linked to BADBOX.

The Hacker News

Kaspersky said it found a malware family that targeted Android-based vehicle head unit firmware from DoFun. Dmitry Kalinin said the infection chain was specific to that device class and was the first documented case of its kind on a car head unit.

The activity was attributed with high confidence to MoYu Group. HUMAN Satori Threat Intelligence and Research team had previously linked that group to BADBOX, and Google filed a lawsuit in July 2025 against 25 unnamed individuals or entities in China over the botnet and its infrastructure.

Kaspersky said the malware abused TWCore, a legitimate system app called com.tw.core, to collect analytics and download APK files through a message broker hosted on a cardoor.cn subdomain. The update path was used to deliver a dropper called JarService.

After installation, the malware ran without a user interface and sent device and configuration data to a command server about every 90 minutes. Kaspersky said the server could return updated settings or command identifiers, and the malware could show adverts, carry out ad fraud, fetch extra modules and collect device details.

Kaspersky said the operators used the loadlib2 and http commands to obtain zhima, a reverse proxy module that Nokia Deepfield Emergency Response Team had documented the previous month. The company said the issue that allowed the software distribution abuse had been fixed after responsible disclosure.

Named in this story

People

Dmitry Kalinin
commented on the malware as a security researcher

Companies

Kaspersky
discovered the threat in June 2026
DoFun
developed the Android-based vehicle head unit firmware targeted in the campaign
Google
filed a lawsuit in July 2025 over the BADBOX botnet and its infrastructure

Organisations

MoYu Group
was attributed with high confidence to the activity
HUMAN Satori Threat Intelligence and Research team
previously linked MoYu Group to the BADBOX scheme
Nokia Deepfield Emergency Response Team
documented zhima the previous month

Products and systems

BADBOX
was the ad fraud and residential proxy scheme tied to the group
TWCore
was the legitimate system app used to collect analytics and fetch updates
JarService
was the dropper used to deliver the malware
zhima
was the reverse proxy module downloaded by the malware

How the source tells it

The article used a threat-intelligence register that mixed reporting with novelty and urgency framing.

  • urgency ends with a warning that vehicle platforms need urgent protection
  • novelty leans on first-case language and repeated emphasis on newness
  • threat inflation suggests broad scale with phrases about widespread compromise and a huge share of apps without counting it
  • sophistication hype describes the delivery route as more advanced than earlier methods without showing a benchmark