JarService is an Android Trojan dropper targeting automotive infotainment head units running DoFun software. Discovered in June 2026, it serves as the first stage of a multistage infection chain used for advertising fraud and residential proxy botnet operations. The campaign is attributed with high confidence to MoYu Group, a cybercrime actor associated with the BADBOX ecosystem, based on malware artifacts and overlapping infrastructure.
Attackers distribute JarService by abusing TWCore, a legitimate system application responsible for analytics and software updates on affected head units. TWCore receives installation instructions through MQTT and can install applications absent from the original firmware. Abuse of this functionality allows silent installation without driver interaction. JarService has no user interface and decrypts embedded XOR-obfuscated data containing the next-stage payload, version information, and execution entry point before loading that payload.
The subsequent loader contacts command-and-control infrastructure and retrieves an encrypted third-stage payload. These later components collect device and network information, accept remote commands, perform HTTP requests, open web content, execute JavaScript, and download and execute additional code. Operators used this functionality to deploy the zhima reverse-proxy module, enabling third-party traffic to pass through compromised head units. Advertising and fraudulent-click functionality is also present in the downstream payloads. These capabilities belong to the subsequent stages rather than the minimal JarService dropper itself. DoFun reported addressing the security issues that enabled the distribution mechanism.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kaspersky researchers determined the Android malware, dubbed JarService, was targeting modules made by DoFun, a Chinese automotive technology manufacturer.
The first component, JarService, has no user interface. It decrypts embedded data and starts the next payload, keeping the infection out of a driver’s view.
The unknown app has no interface and is a piece of malware called JarService. When launched, the malware decrypts and executes a second-stage loader that establishes communication with a command-and-control (C2) server and downloads another encrypted payload.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Kaspersky traced the infections to TWCore, a legitimate system application installed on DoFun devices that collects analytics and handles software updates. TWCore can also download and install new Android applications. According to the report, attackers abused that functionality to push a malicious app called JarService onto affected devices
Le malware est distribué via TWCore ( com.tw.core ), une application système légitime responsable des mises à jour du firmware. TWCore reçoit des instructions via un broker MQTT hébergé sur cardoor[.]cn , qui lui ordonne de télécharger et d’installer des APK malveillants.
Stage 3 – Clicker / Reverse proxy loader : Contacte le C2 toutes les 90 minutes, reçoit des commandes ( loadlib2 , http , web , deeplink , traceroute , etc.), télécharge et exécute le module zhima (proxy inversé).
Исследователи обнаружили в коде вредоноса поддержку девяти команд, среди которых были открытие страниц в WebView, выполнение JavaScript, HTTP-запросы и загрузка произвольного кода.
TWCore reçoit des instructions via un broker MQTT hébergé sur cardoor[.]cn , qui lui ordonne de télécharger et d’installer des APK malveillants. Le champ installNotExists permet l’installation d’applications absentes du dispositif à l’origine.
Stage 1 – JarService (dropper) : Application sans interface utilisateur, déchiffre des blocs XOR pour charger le payload suivant.
The third stage checks in at regular intervals... then receives fresh configuration data or commands.
http - Sends HTTP GET or POST requests and can save part of the response
Stage 2 – Loader : Envoie des informations sur l’implant au C2 via POST, reçoit en retour un lien de téléchargement pour le stage 3.
66 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multistage Android downloader targeting DoFun automotive infotainment head units. Attackers distribute it by abusing the legitimate TWCore firmware updater's ability to install software not already present. It ultimately deploys an unnamed click-fraud Trojan and a reverse-proxy module. Kaspersky attributed the campaign to MoYu Group with high confidence. The affected modules reportedly pose no physical risk to occupants; remediation of already infected units remains unclear, although DoFun reported fixing the security issues.
Android malware stage 1/dropper delivered via the compromised TWCore update mechanism; it decrypts XOR-obfuscated blocks to load the next payload in a multi-stage infection chain targeting DoFun head units.
Android malware delivered to DoFun car head units via abuse of the legitimate TWCore application. It operates without a visible UI, downloads additional malicious code, can display ads and generate fraudulent ad clicks, and includes modules that turn infected head units into reverse proxies as part of a botnet.
A first-stage dropper used in the head-unit infection chain to unpack and pass execution to the next malware stage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.