JarService is an Android dropper used in a multi-stage malware campaign targeting Android-based automotive head units, particularly DoFun devices. It is a small application with no user interface that is covertly installed through abuse of the legitimate TWCore system application's software update mechanism. The campaign has been assessed with high confidence as linked to MoYu Group, an actor associated with the BADBOX ecosystem.
JarService functions as the first stage of the infection chain. It decrypts embedded data blocks containing versioning information, code, and the entry point for the next-stage payload, then launches a second-stage loader. That loader uses encrypted strings and Java reflection to execute a third-stage component, reports implant information to command-and-control infrastructure, and retrieves additional payloads. The later stages support dynamic configuration updates and command-based tasking, including HTTP request execution, WebView-driven activity, deeplink handling, traceroute-style network checks, clipboard-related actions, and arbitrary code loading.
Observed operations show the malware chain being used for covert monetization and infrastructure abuse. In particular, the third stage can download and execute the zhima reverse-proxy module, turning infected devices into nodes in a proxy botnet. The broader campaign also supports ad-fraud activity. JarService is therefore best understood as the initial dropper in a staged Android malware framework designed to establish follow-on payload delivery and enable monetization and proxy services on compromised automotive head units.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Next, we’ll break down the malware installed by TWCore: the JarService dropper. Stage 1: the JarService dropper As mentioned earlier, JarService is a small dropper app with no UI of any kind.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Оно расшифровывает данные, которые хранятся в коде троянца в виде зашифрованных блоков. Для каждого блока применяется XOR-шифрование
в его коде содержатся зашифрованные строки, используемые в дальнейшем в качестве имен классов для выполнения полезной нагрузки третьего этапа с помощью рефлексии
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stage-1 Android dropper installed via compromised automotive head unit update functionality. It decrypts embedded payload metadata and code, then loads the next-stage malicious loader.
Android dropper installed via the legitimate TWCore update mechanism on DoFun head units. It decrypts embedded payload metadata and code, then launches the next-stage loader.
A small Android dropper app with no UI that decrypts embedded data and loads the next-stage payload. It is the first stage in a multi-stage infection chain delivered via compromised automotive head unit firmware updaters, ultimately supporting ad fraud and proxy botnet activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.