Activity timeline
MoYu Group appears in 3 tracked threats between and .
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 2 of 3 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1090.002 External Proxy — Command and Controlobserved in 2 of 3 tracked threats
- T1195.002 Compromise Software Supply Chain — Initial Accessobserved in 2 of 3 tracked threats
- T1406 Obfuscated Files or Information — Defense Evasion (Mobile)observed in 2 of 3 tracked threats
- T1407 Download New Code at Runtime — Defense Evasion (Mobile)observed in 2 of 3 tracked threats
- T1422 System Network Configuration Discovery — Discovery (Mobile)observed in 2 of 3 tracked threats
- T1426 System Information Discovery — Discovery (Mobile)observed in 2 of 3 tracked threats
- T1437 Application Layer Protocol — Command and Control (Mobile)observed in 2 of 3 tracked threats
- T1474 Supply Chain Compromise — Initial Access (Mobile)observed in 2 of 3 tracked threats
- T1604 Proxy Through Victim — Defense Evasion (Mobile)observed in 2 of 3 tracked threats
- T1620 Reflective Code Loading — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1643 Generate Traffic from Victim — Impact (Mobile)observed in 2 of 3 tracked threats
- T1016 System Network Configuration Discovery — Discoveryobserved in 1 of 3 tracked threats
Tracked threats
- First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox BotnetHIGH
- JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX BotnetHIGH
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetHIGH