Cybersecurity
Android car malware used built-in updaters
Kaspersky said a malware family targeted DoFun Android vehicle head units by abusing their update process, with the activity attributed to MoYu Group and linked to BADBOX.
- Kaspersky said it found the malware in June 2026 and that it was intended to support ad fraud and a proxy botnet.
- The malware spread through internal update mechanisms in DoFun’s Android-based vehicle head unit firmware, and the issue was addressed after responsible disclosure.
- Kaspersky attributed the activity with high confidence to MoYu Group, which HUMAN Satori had previously linked to BADBOX, and Google sued 25 unnamed parties in China in July 2025 over that botnet.
- The delivery chain used TWCore and JarService, and the malware later contacted a command server every 90 minutes and could receive configuration changes or commands.
Kaspersky said it found a malware family that targeted Android-based vehicle head unit firmware from DoFun. Dmitry Kalinin said the infection chain was specific to that device class and was the first documented case of its kind on a car head unit.
The activity was attributed with high confidence to MoYu Group. HUMAN Satori Threat Intelligence and Research team had previously linked that group to BADBOX, and Google filed a lawsuit in July 2025 against 25 unnamed individuals or entities in China over the botnet and its infrastructure.
Kaspersky said the malware abused TWCore, a legitimate system app called com.tw.core, to collect analytics and download APK files through a message broker hosted on a cardoor.cn subdomain. The update path was used to deliver a dropper called JarService.
After installation, the malware ran without a user interface and sent device and configuration data to a command server about every 90 minutes. Kaspersky said the server could return updated settings or command identifiers, and the malware could show adverts, carry out ad fraud, fetch extra modules and collect device details.
Kaspersky said the operators used the loadlib2 and http commands to obtain zhima, a reverse proxy module that Nokia Deepfield Emergency Response Team had documented the previous month. The company said the issue that allowed the software distribution abuse had been fixed after responsible disclosure.
Named in this story
People
- Dmitry Kalinin
- commented on the malware as a security researcher
Companies
- Kaspersky
- discovered the threat in June 2026
- DoFun
- developed the Android-based vehicle head unit firmware targeted in the campaign
- filed a lawsuit in July 2025 over the BADBOX botnet and its infrastructure
Organisations
- MoYu Group
- was attributed with high confidence to the activity
- HUMAN Satori Threat Intelligence and Research team
- previously linked MoYu Group to the BADBOX scheme
- Nokia Deepfield Emergency Response Team
- documented zhima the previous month
Products and systems
- BADBOX
- was the ad fraud and residential proxy scheme tied to the group
- TWCore
- was the legitimate system app used to collect analytics and fetch updates
- JarService
- was the dropper used to deliver the malware
- zhima
- was the reverse proxy module downloaded by the malware
How the source tells it
The article used a threat-intelligence register that mixed reporting with novelty and urgency framing.
- urgency ends with a warning that vehicle platforms need urgent protection
- novelty leans on first-case language and repeated emphasis on newness
- threat inflation suggests broad scale with phrases about widespread compromise and a huge share of apps without counting it
- sophistication hype describes the delivery route as more advanced than earlier methods without showing a benchmark