Updated
Updated · securelist.com · Aug 22
MoYu Group Hijacks Android Car Head Units via 3-Stage Malware as DoFun Fixes Update Flaw
Updated
Updated · securelist.com · Aug 22

MoYu Group Hijacks Android Car Head Units via 3-Stage Malware as DoFun Fixes Update Flaw

3 articles · Updated · securelist.com · Aug 22

Summary

  • Kaspersky traced a first-known car head-unit malware campaign to MoYu Group, finding Android devices infected through built-in firmware updaters and then turned into ad-fraud tools and proxy botnet nodes.
  • TWCore, a legitimate DoFun system app, installed rogue APKs pushed through cardoor[.]cn update messages; the chain dropped JarService, fetched a second-stage loader and then a third-stage payload.
  • Every 90 minutes, the final malware checked in with command servers, pulled updated configurations and executed commands including web ad-click activity and the "zhima" reverse-proxy module.
  • Kaspersky linked the operation to MoYu Group with high confidence through shared infrastructure and code patterns tied to BADBOX-related activity; Nokia researchers separately found the same zhima module on TV set-top boxes.
  • DoFun said it fixed the security issues after notification, but the case shows attackers expanding BADBOX-style monetization into automotive Android platforms through legitimate update channels.

Insights

Could your car's infotainment system be secretly working for a global botnet while you drive?
How many other smart devices are quietly running ad fraud proxies through trusted supply chain updates?