MoYu Group is a threat actor linked with high confidence to the BADBOX botnet ecosystem, including BADBOX 2.0, and is associated with covert monetization of compromised Android-based consumer and embedded devices. The group has been tied to operations affecting Android smartphones, tablets, streaming devices, TV boxes, and Android-based automotive head units. Its activity is consistent with financially motivated abuse of infected devices for ad fraud and residential or reverse-proxy services. MoYu Group has been associated with a multi-stage Android malware campaign targeting aftermarket car infotainment head units running DoFun software, assessed as the first documented malware infection chain specifically tailored to that device class. In that operation, the actors abused a legitimate system update component to silently install malicious Android applications without user interaction. The malware chain included dropper, loader, clicker, downloader, and reverse-proxy functionality. Observed behavior showed the operators primarily deploying a reverse-proxy module, indicating an objective of enrolling devices into a proxy botnet while retaining the ability to deliver additional payloads. Across reporting, MoYu Group is linked to BADBOX operations that have used both supply-chain-style preinstallation on low-cost Android devices and post-sale compromise through legitimate update paths. The group’s tooling supports remote command execution through application-level tasking, device profiling, periodic beaconing, dynamic configuration updates, hidden web content loading, HTTP-based task execution, and arbitrary module loading. Documented capabilities include ad display, fraudulent ad clicking, device information collection, payload staging, and conversion of infected devices into traffic-relay nodes for proxy infrastructure. Attribution to MoYu Group is supported by overlaps in infrastructure, malware naming conventions, shared components, and links to other BADBOX-associated Android malware. The actor has also been named alongside other BADBOX-related entities including SalesTracker Group, Lemon Group, and LongTV. MoYu Group should be understood as part of a broader Chinese-linked criminal ecosystem focused on monetizing large populations of compromised Android and IoT-like devices rather than as a traditional espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
72 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linked to development and operation of the BadBox botnet and assessed as likely responsible for malware targeting Android-based car head units via a compromised software update channel, apparently to enroll devices into a proxy botnet and support fraud-related activity.
Operating an Android malware campaign infecting DoFun Android-based car head units via abuse of the TWCore system application to install JarService, with the apparent goal of expanding a botnet and using infected devices as reverse proxies, ad-fraud nodes, and downloader footholds.
Attributed operator behind Android malware delivered via built-in updaters on Android-based car head units, using the infections for ad fraud and to build a proxy botnet.
Attributed with high confidence to a campaign targeting Android-based automotive head units via a legitimate software update mechanism, delivering JarService and the zhima reverse-proxy module to monetize infected devices and expand a proxy botnet.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.