Researchers reported the first documented Android malware campaign targeting automotive head units, after attackers abused the legitimate update mechanism of the TWCore system app on DoFun devices to deliver a multi-stage infection chain. The campaign used a stage-1 dropper known as JarService, followed by a stage-2 loader and a stage-3 payload that enabled ad-click fraud and deployed the zhima reverse-proxy module. Kaspersky said the operation was discovered in June 2026 and that DoFun later fixed the security issues that allowed the malicious updates to be distributed.
The activity was attributed with high confidence to MoYu Group, an actor tied to the broader BADBOX ecosystem previously linked to large-scale fraud operations on consumer Android devices. HUMAN Security's reporting on BADBOX 2.0 described a botnet monetizing infected devices through multiple schemes, including ad fraud and proxy abuse, aligning with the tactics seen in the automotive infections. The overlap in infrastructure and naming suggests the operators extended BADBOX-style monetization from consumer electronics into internet-connected vehicles, creating a new foothold inside Android-based in-car systems.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Kaspersky published a Securelist analysis detailing the multi-stage Android malware campaign targeting automotive head units, including the TWCore abuse chain, malware stages, and reverse-proxy/ad-fraud functionality. The report also disclosed infrastructure, URLs, domains, and file hash indicators associated with the activity.
Researchers identified a new multi-stage Android malware campaign in June 2026 targeting Android-based automotive head units for ad fraud and proxy botnet activity. The malware was distributed through the legitimate TWCore update mechanism on DoFun head units.
HUMAN Security published a report on BADBOX 2.0 describing the disruption of a campaign targeting consumer devices with multiple fraud schemes.
After being notified about the distribution scheme affecting its head units, DoFun reported that it had fixed the security issues that enabled the malware delivery path.
Researchers attributed the automotive head-unit malware activity with high confidence to MoYu Group based on naming overlaps and shared infrastructure. The actor was described as linked to the BADBOX botnet.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 66 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
11 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcecyberveille.ch
Open sourcesecurelist.ru
Open sourcesecurelist.com
Open sourcehumansecurity.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.