ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

Malware hit Android car head units through DoFun app

Kaspersky said a supply-chain attack used a legitimate DoFun update app to install JarService on Android car head units, with the operation linked to MoYu and aimed at proxy abuse and ad fraud.

BleepingComputer

Kaspersky researchers said they analysed a supply-chain attack against Android-based car head units and attributed it to the MoYu group. They said MoYu had previously been linked to the BadBox malware botnet.

The target was DoFun, which Kaspersky described as an automotive software, cloud services and hardware provider owned by Shenzhen Driving Control Technology Co., Ltd. The company sold generic Android-based head units for vehicle infotainment, navigation and settings.

In June, the researchers found a rogue APK being delivered through DoFun’s TWCore system app. They said TWCore received instructions from an MQTT server at cardoor[.]cn, and the malware was named JarService.

Kaspersky said JarService decrypted and ran a second-stage loader, which then connected to a command-and-control server and fetched another encrypted payload. The final payload reported device details and accepted commands, including actions for browser use, downloads and network checks.

The researchers said the operator mainly loaded a reverse-proxy module called zhima and also made web requests linked to click fraud. Kaspersky said the malware did not interfere with driving or critical vehicle control systems, and that DoFun said it had resolved the issue after being notified.

Named in this story

Companies

Kaspersky
analysed the malware and reported its findings
DoFun
was the target system provider and said it resolved the issue
Shenzhen Driving Control Technology Co., Ltd.
owned DoFun

Organisations

MoYu group
was identified by Kaspersky as the actor behind the operation

Products and systems

BadBox malware botnet
was the earlier campaign MoYu had been linked to
TWCore
was the legitimate DoFun system app used to deliver the rogue APK
JarService
was the malware installed on the head units
zhima
was the reverse-proxy module loaded by the operator

Places

cardoor[.]cn
hosted the MQTT server used for instructions

How the source tells it

The article was a straight technical security report with a small amount of novelty framing and one reassurance about vehicle safety.

  • novelty it framed the infection chain as the first documented case for that type of target
  • reassurance it explicitly stated the malware did not affect driving or critical control systems