MoYu Group Hijacks Android Car Head Units via 3-Stage Malware as DoFun Fixes Update Flaw
Updated
Updated · securelist.com · Aug 22
MoYu Group Hijacks Android Car Head Units via 3-Stage Malware as DoFun Fixes Update Flaw
3 articles · Updated · securelist.com · Aug 22
Summary
Kaspersky traced a first-known car head-unit malware campaign to MoYu Group, finding Android devices infected through built-in firmware updaters and then turned into ad-fraud tools and proxy botnet nodes.
TWCore, a legitimate DoFun system app, installed rogue APKs pushed through cardoor[.]cn update messages; the chain dropped JarService, fetched a second-stage loader and then a third-stage payload.
Every 90 minutes, the final malware checked in with command servers, pulled updated configurations and executed commands including web ad-click activity and the "zhima" reverse-proxy module.
Kaspersky linked the operation to MoYu Group with high confidence through shared infrastructure and code patterns tied to BADBOX-related activity; Nokia researchers separately found the same zhima module on TV set-top boxes.
DoFun said it fixed the security issues after notification, but the case shows attackers expanding BADBOX-style monetization into automotive Android platforms through legitimate update channels.