Researchers uncovered a new Android malware family that targets DoFun vehicle head unit firmware by abusing legitimate software update mechanisms to install hidden payloads. The campaign, linked to the MoYu Group and BADBOX activity, supports ad fraud and proxy botnet operations while stealing device details and fetching additional modules like zhima. #DoFun #MoYuGroup #BADBOX #TWCore #JarService #zhima
Keypoints
- The malware is the first documented threat to infect Android car head units through a device-specific chain.
- It abuses the TWCore update process on DoFun-based firmware to deliver a dropper called JarService.
- The payload installs as a hidden app and checks in to its C2 server every 90 minutes.
- It can display ads, perform ad fraud, and download extra malicious modules.
- The campaign is attributed to MoYu Group and overlaps with the BADBOX botnet ecosystem.
Read More: https://thehackernews.com/2026/08/android-car-malware-spreads-through.html