Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Android Car Malware Spreads Through Built-In Updaters for Ad (TL-2026-2100), also tracked as BadBox Car Campaign, is a high-severity malware campaign, first published 2026-08-21 and last reviewed 2026-08-23. It is attributed to MoYu Group (China) with high confidence, affects DoFun Android-based car head unit firmware, maps to 22 MITRE ATT&CK techniques (T1016, T1027, T1036), and is covered by 9 detection rules and 32 indicators of compromise.
Key facts for TL-2026-2100
- Threat ID
- TL-2026-2100
- Also known as
- BadBox Car Campaign, MoYu Car Botnet, DoFun Head Unit Malware
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-08-21
- Last reviewed
- 2026-08-23
- Attribution
- MoYu Group
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- automotive, transport, consumer-electronics
- Target regions
- Worldwide
- Detection rules
- 9
- Indicators of compromise
- 32
- Updates
- 2026-08-23 · revalidated 1× · latest source
Malware and tooling in Android Car Malware Spreads Through Built-In Updaters for Ad
Malware and tooling: BadBox, JarService, Trojan, zhima
Kaspersky researcher Dmitry Kalinin discovered a novel Android malware family in June 2026 targeting DoFun car head unit firmware — the first documented case of malware with an infection chain specifically designed for automotive head units. The malware spreads through the legitimate TWCore system app's OTA update mechanism via MQTT, functioning as a multi-stage downloader enabling ad fraud and proxy botnet creation. Attributed with high confidence to MoYu Group, the threat actor behind the BADBOX 2.0 ecosystem.
How Android Car Malware Spreads Through Built-In Updaters for Ad works
In June 2026, Kaspersky researcher Dmitry Kalinin identified a sophisticated multi-stage Android malware campaign targeting automotive head units manufactured by DoFun — a Chinese company that develops firmware, apps, and cloud services for Android-based car infotainment systems serving over 30 million vehicle owners worldwide. This represents the first documented case of malware specifically designed for and distributed through car head unit infection chains.
The infection vector exploits TWCore (com.tw.core), a legitimate system application pre-installed on DoFun head units responsible for collecting analytics and performing over-the-air (OTA) software updates. TWCore communicates with an MQTT message broker hosted at cardoor.cn to receive installation instructions. A Boolean flag called 'installNotExists' in the MQTT message allows TWCore to install applications that were not originally present on the device — a design feature that attackers weaponized to deliver the JarService Trojan dropper.
The malware operates across four stages. Stage 1 (JarService) is a small dropper APK with no user interface that contains XOR-encrypted payload blocks, each encrypted with a single-byte key that shifts linearly between blocks. The decrypted data reveals payload version information, an entry point class (wa method of com.c.j.qbh), and the next-stage loading code. Stage 2 decrypts runtime strings and uses Java reflection to invoke and execute Stage 3. It sends device information to the C2 server via an HTTP POST to obtain the next-stage payload URL (e.g., 144.217.243.201/vr34der34/dex3.68.png). Seven distinct payload variants were retrieved by Kaspersky through version number probing, with the earliest being version 3.57 using a different decoding algorithm.
Stage 3 operates as a clicker and reverse proxy loader, beaconing to the C2 endpoint /cpc/api/task every 90 minutes by default. The beacon payload includes device display resolution, model identifier, connected Wi-Fi SSID, MAC address, and the Trojan's configuration version. If the C2 determines the configuration is outdated, it returns updated C2 addresses (on .sbs TLD domains), new API paths, and interval settings — the most recent config version observed was 3.82. If new command identifiers (productId values) are present, the malware fetches their definitions from /cpc/api/xml.
The malware supports nine distinct commands stored as serialized JSON in SharedPreferences: return (retrieve stored values), copy (set clipboard contents), http (arbitrary HTTP POST/GET requests), web (open WebView and execute arbitrary JavaScript), loadlib2 (download and execute arbitrary code from a URL), deeplink (open browser URLs), and traceroute (ICMP ping checks). Commands loadlib and loadlib3 are not yet fully implemented. In observed attacks, only loadlib2 and http were actively used.
Through the loadlib2 and http commands, attackers deliver the zhima reverse proxy module — downloaded from URLs like 144.217.243.201/vr34der34/sh65.io with eight documented variants (earliest version 57). Zhima converts infected head units into residential proxy nodes by instantiating the module with C2 IPs (107.151.248.132, 128.14.210.58), proxy ports (1337/9999, 7777, 8888), and a 15-second timeout. The domain admin.uipoxy.com resolves to 128.14.210.58 and hosts the zhima administrative panel at /proxy/u/login, requiring an invite code for registration.
Kaspersky identified links between MoYu Group and two residential proxy services: PXYEDGE (pxyedge.com) and ProxyForU (proxyforu.com). Both offer residential proxy services that route paying clients' traffic through infected devices, and share identical API patterns — sign-in on admin.* subdomains at /proxy/u/login and signup at /proxy/register?channelKey=<invitation code>. Researchers assess these services are directly connected to MoYu Group.
The operation is attributed with high confidence to MoYu Group, previously exposed by HUMAN Security's Satori team as a key operator within the BADBOX 2.0 malware ecosystem — a massive botnet that infected over 1 million off-brand Android Open Source Project (AOSP) devices. In July 2025, Google filed a federal lawsuit in New York against 25 unnamed Chinese entities for operating BADBOX 2.0 under the Computer Fraud and Abuse Act and RICO Act. Despite multiple disruption efforts including a December 2024 sinkhole by Germany's BSI affecting ~30,000 devices and a March 2025 sinkhole of BADBOX 2.0 domains disrupting 500,000+ devices, individual actors continue their malicious activities.
Nokia Deepfield's Emergency Response Team independently confirmed the same zhima reverse proxy module on TV set-top boxes, corroborating the campaign's infrastructure expansion from Android TV devices into automotive platforms. Following responsible disclosure, DoFun reported fixing the security issues in their firmware update mechanism. However, Kaspersky warns that individual actors associated with the campaign continue infecting devices worldwide.
MITRE ATT&CK techniques used in TL-2026-2100
Discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1518 Software Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
Command and Control
T1071 Application Layer Protocol; T1071.001 Web Protocols; T1090 Proxy; T1090.002 External Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools
Collection
Initial Access
T1195.002 Compromise Software Supply Chain
Impact
Persistence
T1554 Compromise Host Software Binary
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587.001 Malware
Affected products and versions in Android Car Malware Spreads Through Built-In Updaters for Ad
- DoFun — Android-based car head unit firmware
Vulnerable versions: All firmware versions before security fix (June 2026)
Fixed in: Post-June 2026 firmware update
Remediation for Android Car Malware Spreads Through Built-In Updaters for Ad
Patches
- Apply the latest official DoFun firmware update (vendor has reported fixing the security issues)
Immediate actions
- Check head units for unauthorized apps (JarService, com.tw.jar1) using package manager
- Block C2 domains at network perimeter: cardoor.cn, all *.sbs domains, admin.uipoxy.com, pxyedge.com, proxyforu.com
- Block C2 IPs: 144.217.243.201, 107.151.248.132, 128.14.210.58
- Monitor for anomalous outbound HTTP POSTs to /cpc/api/task or /cpc/api/report endpoints
- Inspect TWCore external cache directory for files under push/apk/ path
Workarounds
- Disable unnecessary internet connectivity on head units where feasible
- Audit and remove the TWCore update channel if not required
- Restrict outbound MQTT traffic to only known update servers
Longer-term hardening
- Implement firmware integrity validation and code signing for all OTA updates
- Restrict MQTT-based update mechanisms to allow only vendor-signed content
- Deploy network segmentation for automotive head units away from critical vehicle systems
- Establish behavioral detection rules for Java reflection-based code loading on Android devices
- Implement supply-chain security reviews for third-party firmware components
Timeline of Android Car Malware Spreads Through Built-In Updaters for Ad
- Original BADBOX scheme publicly disclosed and disrupted by HUMAN Security's Satori team
- Earliest known JarService dropper variant uploaded to DoFun update infrastructure via cardoor.cn
- Germany's Federal Office for Information Security (BSI) sinkholes ~30,000 BadBox-infected devices
- HUMAN Security officially discloses BADBOX 2.0 operation; 500,000+ devices sinkholed via Shadowserver Foundation
- HUMAN Security's Satori Threat Intelligence team, working with Google, Trend Micro, and Shadowserver, publicly discloses and partially disrupts BADBOX 2.0 infrastructure and formally exposes MoYu Group as an operator.
- Additional JarService variant observed on DoFun update infrastructure
- Google files federal lawsuit in New York against 25 unnamed Chinese entities for operating BADBOX 2.0 under CFAA and RICO
- Latest JarService variant observed; Kaspersky researcher Dmitry Kalinin discovers the car head unit malware campaign
- Kaspersky notifies DoFun about the distribution scheme; vendor reports fixing the security issues
- Nokia Deepfield Emergency Response Team independently confirms zhima reverse proxy module on TV set-top boxes, corroborating infrastructure overlap
- Public disclosure by Kaspersky and The Hacker News; first documented malware campaign targeting car head units revealed
Update history for TL-2026-2100
- 2026-08-23 — MoYu Group Malware Hijacks Android Car Head Units via Firmware Updaters for Proxy Botnet and Ad Fraud: What changed Core severity/exploitability/status/attribution unchanged (HIGH / ACTIVE / ACTIVE / MoYu Group, HIGH confidence). No escalation evidence in the newer report. New indicators (9) 3 new C2 domains (kookjar.com, ty54fgd435.my, ue88
Sources cited for Android Car Malware Spreads Through Built-In Updaters for Ad
- Android Car Malware Spreads Through Built-In Updaters
- First Android malware targeting automotive head units (Securelist)
- Botnet on the road: the first trojan for car head units (Kaspersky Blog)
- BadBox-linked Android malware has now infected car head units
- Google taking legal action against the BadBox 2.0 botnet
- Satori: Inside the Disruption of BADBOX 2.0
- Google sues to disrupt BadBox 2.0 botnet infecting 10 million devices
- Nokia Deepfield Public Research (zhima/ipmoyu)
- Android Head Unit Malware Recruits Vehicles into Botnet
- Android Car Head-Unit Malware Linked to BadBox
Threats related to Android Car Malware Spreads Through Built-In Updaters for Ad
Detection coverage for TL-2026-2100
As of 2026-08-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2100 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.