# MoYu Group

> As of 2026-08-25, MoYu Group is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware. ATT&CK coverage spans 43 techniques across 18 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1071.001 (Web Protocols), T1082 (System Information Discovery).

- **Nation:** China
- **Tracked threats:** 3
- **Categories:** MALWARE
- **As of:** 2026-08-25

## ATT&CK techniques observed

43 techniques observed across 3 of 3 tracked threats. Tactics: Command and Control (6), Resource Development (5), Defense Evasion (Mobile) (4), Stealth (formerly Defense Evasion) (4), Command and Control (Mobile) (3), Discovery (3).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 3 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1090.002](https://intel.threadlinqs.com/technique/T1090.002) External Proxy — Command and Control — observed in 2 of 3 tracked threats
- [T1195.002](https://intel.threadlinqs.com/technique/T1195.002) Compromise Software Supply Chain — Initial Access — observed in 2 of 3 tracked threats
- [T1406](https://intel.threadlinqs.com/technique/T1406) Obfuscated Files or Information — Defense Evasion (Mobile) — observed in 2 of 3 tracked threats
- [T1407](https://intel.threadlinqs.com/technique/T1407) Download New Code at Runtime — Defense Evasion (Mobile) — observed in 2 of 3 tracked threats
- [T1422](https://intel.threadlinqs.com/technique/T1422) System Network Configuration Discovery — Discovery (Mobile) — observed in 2 of 3 tracked threats
- [T1426](https://intel.threadlinqs.com/technique/T1426) System Information Discovery — Discovery (Mobile) — observed in 2 of 3 tracked threats
- [T1437](https://intel.threadlinqs.com/technique/T1437) Application Layer Protocol — Command and Control (Mobile) — observed in 2 of 3 tracked threats
- [T1474](https://attack.mitre.org/techniques/T1474/) Supply Chain Compromise — Initial Access (Mobile) — observed in 2 of 3 tracked threats
- [T1604](https://attack.mitre.org/techniques/T1604/) Proxy Through Victim — Defense Evasion (Mobile) — observed in 2 of 3 tracked threats
- [T1620](https://intel.threadlinqs.com/technique/T1620) Reflective Code Loading — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1643](https://attack.mitre.org/techniques/T1643/) Generate Traffic from Victim — Impact (Mobile) — observed in 2 of 3 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 1 of 3 tracked threats

## Tracked threats

- [First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox Botnet](https://intel.threadlinqs.com/threat/TL-2026-2137) — HIGH
- [JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet](https://intel.threadlinqs.com/threat/TL-2026-2111) — HIGH
- [Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet](https://intel.threadlinqs.com/threat/TL-2026-2100) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/MoYu%20Group
