A newly identified malware family has been infecting Android-based vehicle head units built on DoFun firmware by abusing the devices’ built-in software update mechanism. Kaspersky said the campaign, attributed to the MoYu Group and linked to prior BADBOX activity, is the first documented malware infection chain tailored specifically for car head units. The attackers abuse the legitimate TWCore system app to deliver a dropper named JarService, which launches a loader that reaches out to command-and-control infrastructure for additional payloads.
The malware is designed to monetize compromised in-car systems through ad fraud while also turning them into a proxy botnet. Reported capabilities include displaying ads, downloading additional malware, collecting device information, and deploying the reverse proxy module zhima. Supporting indicators tied to the activity include suspicious Android package names, rotating .sbs domains, IP addresses, APK delivery URLs, and infrastructure associated with proxy services and payload hosting under cardoor[.]cn, indicating a broader Android malware ecosystem behind the operation.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
A third APK download URL listed in the indicator reference is dated 2026-06-08 under ovcloudcontrol.cdn.cardoor[.]cn, tying the delivery infrastructure to activity in June 2026.
Kaspersky discovered a malware family targeting Android-based vehicle head unit firmware developed by DoFun. The malware spreads through built-in firmware updaters and is described as the first documented infection chain tailored specifically for car head units.
The indicator-only reference includes another APK download URL under ovcloudcontrol.cdn.cardoor[.]cn dated 2025-06-10, showing continued use of the same delivery infrastructure.
One reference lists an APK download URL under ovcloudcontrol.cdn.cardoor[.]cn that is dated 2024-11-07, indicating malware-related payload hosting infrastructure was active by that date.
After responsible disclosure by Kaspersky, DoFun stated that it had fixed the issue affecting its Android-based car head unit firmware. This is the first explicit vendor remediation/response event described in the timeline.
The activity targeting DoFun Android car head units was attributed to the MoYu Group, which had previously been linked to the BADBOX botnet. Reported capabilities included ad fraud, additional malware delivery, device information collection, and deployment of the zhima reverse proxy module.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 72 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcecyberveille.ch
Open sourcetherecord.media
Open sourcehelpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.