JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet — Threadlinqs Intelligence
As of 2026-08-23, JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet is a high-severity malware threat attributed to MoYu Group, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 92 indicators of compromise.
Threat ID: TL-2026-2111 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Updated: 2026-08-23 · revalidated 1× · latest source
Attribution: MoYu Group · FINANCIAL
Kaspersky documented the first known Android malware campaign targeting automotive head units: a three-stage infection chain (JarService dropper -> loader -> Zhima reverse-proxy module) delivered by
In August 2026, Kaspersky researcher Dmitry Kalinin published Securelist analysis of the first documented Android malware family built specifically to compromise automotive infotainment ("head unit") systems. The victim platform is DoFun, an Android-based automotive head-unit vendor that Kaspersky states serves over 30 million vehicle owners globally. The infection vector abuses TWCore (package `com.tw.core`), a legitimate, pre-installed DoFun system application responsible for analytics and OTA software updates. TWCore receives update instructions over an MQTT message broker hosted at `cardoor.cn`, and Kaspersky found that when the broker's `installNotExists` flag is set to `true`, TWCore will silently install an APK without first checking whether it is already present on the device and without validating any code-signing signature on the downloaded package. Attackers abused this design flaw to push a malicious APK, JarService, from `ovcloudcontrol.cdn.cardoor.cn`, with build artifacts observed dating back to at least November 2024 and as recently as June 2026.
JarService is a headless, UI-less dropper (entry class `com.c.j.qbh`, method `wa`) that stores its payload as XOR-encrypted code blocks using a linearly shifting single-byte key, and decrypts/launches an intermediate loader (entry point `com.ast.sdk.BillingMain`, method `init`; at least 7 distinct versions observed, 3.57-3.680). The loader beacons device and version metadata (userId, dexVersion, dexType, channelId, packageName, appVersion, appName) to attacker infrastructure over HTTP POST and receives a `dexUrl` pointing to the stage-3 payload, which it decrypts using a single-byte key combined with a four-byte floating-point XOR value. Stage 3 is a clicker/reverse-proxy loader that checks in roughly every 90 minutes (5,500,000 ms) against a `/cpc/api/task` endpoint for configuration (observed configVersion 3.82) and retrieves executable command scripts via `/cpc/api/xml`. The framework implements nine remote commands mapped to individual classes, including `return` (read SharedPreferences), `copy` (clipboard manipulation), `http` (arbitrary HTTP request/response parsing used for ad-fraud and HTTP manipulation), `web` (WebView injection executing arbitrary attacker-supplied JavaScript), `loadlib2` (download and reflectively execute additional Dex code, MD5-verified), `deeplink` (forced browser redirection), and `traceroute` (ICMP reachability probing).
The `loadlib2` command is primarily used to install Zhima, a reverse-proxy module (8 sample variants identified, earliest labeled version 57) that converts the infected head unit into a residential-proxy node, routing third-party traffic through the vehicle's internet connection for monetization. Zhima is administered through a panel at `admin.uipoxy.com/proxy/u/login`, configured with proxy ports 1002, 1337, 7777, 8888, and 15000. Kaspersky attributes the campaign with high confidence to the MoYu Group based on internal thread-naming artifacts ("mosdk-host-loader", where mosdk = MoYu SDK), a related malicious package (`com.abc.nexus`) previously seen on Android TV set-top boxes, a shared service name (`AdmoyuService`) in parallel infrastructure, and network-infrastructure overlap with known MoYu Group C2s. The MoYu Group is separately linked to the BADBOX malicious-platform ecosystem (the Triada-based backdoor family disrupted in its "BADBOX 2.0" form by HUMAN Security, Google, Trend Micro and Shadowserver in March 2025 across more than a million consumer Android/CTV devices), and Kaspersky found the Zhima admin panel's design and copyright strings overlap with the residential-proxy resale services ProxyForU and PXYEDGE, which share the same `/proxy/u/login` authentication API pattern. Nokia's Deepfield Emergency Response Team independently and concurrently identified the Zhima family operating on Android TV set-top boxes, corroborating that the broader operation spans multiple device classes beyond automotive head u
Weaknesses (CWE)
CWE-494, CWE-347, CWE-706, CWE-829, CWE-345
Target sectors: automotive, consumer, advertising
Target regions: Global
Timeline
- Earliest identified JarService dropper build staged at http://ovcloudcontrol.cdn.cardoor.cn/upgrade/2024-11-07/fa831c3c23824b99871163387bcda7ad.apk, indicating the campaign's download infrastructure was active by this date.
- HUMAN Security's Satori team, with Google, Trend Micro and Shadowserver, publicly disclosed and partially disrupted the related BADBOX 2.0 botnet (over 1 million infected consumer/CTV Android devices) -- the malicious platform Kaspersky links the MoYu Group and Zhima activity to.
- Nokia Deepfield dates a host.dex loader sample (com.xgw.f) tied to the same BADBOX module-loading infrastructure to approximately June 2025, predating public disclosure of the automotive campaign.
- FBI/IC3 publishes Public Service Announcement I-060525-PSA warning that the BADBOX 2.0 botnet has compromised millions of IoT devices, including aftermarket vehicle infotainment systems.
- A newer JarService dropper build was staged at http://ovcloudcontrol.cdn.cardoor.cn/upgrade/2025-06-10/fe71af9ecf174de48d2b2ccc2c15fb04.apk.
- Google files a federal lawsuit against 25 China-based entities allegedly operating the BADBOX 2.0 botnet.
- Kaspersky researchers discover the JarService/Zhima infection chain targeting DoFun Android automotive head units.
- Most recent identified JarService build staged at http://ovcloudcontrol.cdn.cardoor.cn/upgrade/2026-06-08/bd80bd3c3d0e4bf6b5b4a825650d01f5.apk, within the window in which Kaspersky researcher Dmitry Kalinin identified the campaign (June 2026).
- Nokia Deepfield independently verifies the zhima/MoYu Zenlayer- and OVH-hosted C2 infrastructure, including overlap with previously published BADBOX apex domains (ad3g.com, moyu88.xyz, ziyemy.shop).
- Nokia Deepfield publishes the 'ipmoyu' public research report detailing MoYu/BADBOX 2.0 infrastructure, the zhima proxy module, and the PXYEDGE/ProxyForU resale brands.
- Kaspersky notifies DoFun of the TWCore MQTT update-validation flaw and the malware campaign; DoFun subsequently reports the issue resolved.
- DoFun confirmed it had fixed the TWCore MQTT update/installNotExists flaw after being notified by Kaspersky, ahead of public disclosure.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 92 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583.001, T1608.001, T1195.002, T1059.007, T1027, T1620, T1082, T1071.001, T1090.002, T1496.002