JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet

JarService/Zhima Multi-Stage Android Malware Targets DoFun (TL-2026-2111) is a high-severity malware campaign, first published 2026-08-22 and last reviewed 2026-08-23. It is attributed to MoYu Group with high confidence, affects DoFun DoFun Android automotive head units (TWCore system app, package, maps to 24 MITRE ATT&CK techniques (T1027, T1059.007, T1071.001), and is covered by 9 detection rules and 92 indicators of compromise.

Key facts for TL-2026-2111

Threat ID
TL-2026-2111
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-08-22
Last reviewed
2026-08-23
Attribution
MoYu Group
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
automotive, consumer, advertising
Target regions
Global
Detection rules
9
Indicators of compromise
92
Updates
2026-08-23 · revalidated 1× · latest source

Malware and tooling in JarService/Zhima Multi-Stage Android Malware Targets DoFun

Malware and tooling: BadBox, JarService, Zhima

Kaspersky documented the first known Android malware campaign targeting automotive head units: a three-stage infection chain (JarService dropper -> loader -> Zhima reverse-proxy module) delivered by abusing the legitimate DoFun TWCore system app's MQTT-based update mechanism. Attributed with high confidence to the MoYu Group and linked to the BADBOX botnet platform, the malware turns infected head units into ad-fraud clickers and residential-proxy nodes.

How JarService/Zhima Multi-Stage Android Malware Targets DoFun works

In August 2026, Kaspersky researcher Dmitry Kalinin published Securelist analysis of the first documented Android malware family built specifically to compromise automotive infotainment ("head unit") systems. The victim platform is DoFun, an Android-based automotive head-unit vendor that Kaspersky states serves over 30 million vehicle owners globally. The infection vector abuses TWCore (package `com.tw.core`), a legitimate, pre-installed DoFun system application responsible for analytics and OTA software updates. TWCore receives update instructions over an MQTT message broker hosted at `cardoor.cn`, and Kaspersky found that when the broker's `installNotExists` flag is set to `true`, TWCore will silently install an APK without first checking whether it is already present on the device and without validating any code-signing signature on the downloaded package. Attackers abused this design flaw to push a malicious APK, JarService, from `ovcloudcontrol.cdn.cardoor.cn`, with build artifacts observed dating back to at least November 2024 and as recently as June 2026.

JarService is a headless, UI-less dropper (entry class `com.c.j.qbh`, method `wa`) that stores its payload as XOR-encrypted code blocks using a linearly shifting single-byte key, and decrypts/launches an intermediate loader (entry point `com.ast.sdk.BillingMain`, method `init`; at least 7 distinct versions observed, 3.57-3.680). The loader beacons device and version metadata (userId, dexVersion, dexType, channelId, packageName, appVersion, appName) to attacker infrastructure over HTTP POST and receives a `dexUrl` pointing to the stage-3 payload, which it decrypts using a single-byte key combined with a four-byte floating-point XOR value. Stage 3 is a clicker/reverse-proxy loader that checks in roughly every 90 minutes (5,500,000 ms) against a `/cpc/api/task` endpoint for configuration (observed configVersion 3.82) and retrieves executable command scripts via `/cpc/api/xml`. The framework implements nine remote commands mapped to individual classes, including `return` (read SharedPreferences), `copy` (clipboard manipulation), `http` (arbitrary HTTP request/response parsing used for ad-fraud and HTTP manipulation), `web` (WebView injection executing arbitrary attacker-supplied JavaScript), `loadlib2` (download and reflectively execute additional Dex code, MD5-verified), `deeplink` (forced browser redirection), and `traceroute` (ICMP reachability probing).

The `loadlib2` command is primarily used to install Zhima, a reverse-proxy module (8 sample variants identified, earliest labeled version 57) that converts the infected head unit into a residential-proxy node, routing third-party traffic through the vehicle's internet connection for monetization. Zhima is administered through a panel at `admin.uipoxy.com/proxy/u/login`, configured with proxy ports 1002, 1337, 7777, 8888, and 15000. Kaspersky attributes the campaign with high confidence to the MoYu Group based on internal thread-naming artifacts ("mosdk-host-loader", where mosdk = MoYu SDK), a related malicious package (`com.abc.nexus`) previously seen on Android TV set-top boxes, a shared service name (`AdmoyuService`) in parallel infrastructure, and network-infrastructure overlap with known MoYu Group C2s. The MoYu Group is separately linked to the BADBOX malicious-platform ecosystem (the Triada-based backdoor family disrupted in its "BADBOX 2.0" form by HUMAN Security, Google, Trend Micro and Shadowserver in March 2025 across more than a million consumer Android/CTV devices), and Kaspersky found the Zhima admin panel's design and copyright strings overlap with the residential-proxy resale services ProxyForU and PXYEDGE, which share the same `/proxy/u/login` authentication API pattern. Nokia's Deepfield Emergency Response Team independently and concurrently identified the Zhima family operating on Android TV set-top boxes, corroborating that the broader operation spans multiple device classes beyond automotive head units. Kaspersky notified DoFun of the distribution scheme prior to publication, and DoFun subsequently confirmed it fixed the underlying TWCore issue. No CVE has been assigned to the `installNotExists` design flaw.

MITRE ATT&CK techniques used in TL-2026-2111

Defense Evasion

T1027 Obfuscated Files or Information; T1406 Obfuscated Files or Information; T1407 Download New Code at Runtime; T1604 Proxy Through Victim; T1620 Reflective Code Loading

Execution

T1059.007 JavaScript; T1623 Command and Scripting Interpreter

Command and Control

T1071.001 Web Protocols; T1090.002 External Proxy; T1437 Application Layer Protocol; T1481 Web Service

Discovery

T1082 System Information Discovery; T1421 System Network Connections Discovery; T1422 System Network Configuration Discovery; T1426 System Information Discovery

Initial Access

T1195.002 Compromise Software Supply Chain; T1474 Supply Chain Compromise

Collection

T1414 Clipboard Data

Impact

T1496.002 Bandwidth Hijacking; T1565.002 Transmitted Data Manipulation; T1643 Generate Traffic from Victim

Persistence

T1577 Compromise Application Executable

Resource Development

T1583.001 Domains; T1608.001 Upload Malware

Affected products and versions in JarService/Zhima Multi-Stage Android Malware Targets DoFun

  • DoFun — DoFun Android automotive head units (TWCore system app, package com.tw.core)
    Vulnerable versions: TWCore builds with installNotExists=true and no APK signature validation, prior to vendor remediation
    Fixed in: TWCore build patched by DoFun after Kaspersky notification, confirmed prior to 2026-08-21

Remediation for JarService/Zhima Multi-Stage Android Malware Targets DoFun

Patches

  • DoFun vendor fix for the TWCore installNotExists design flaw, deployed after Kaspersky's disclosure and confirmed prior to the August 21, 2026 Securelist publication

Immediate actions

  • Block the listed JarService/Zhima C2 domains and IPs (cardoor.cn, xmsae.sbs, ishano456.sbs, xshaon123.sbs, kshahnd.sbs, mdsjhd.sbs, nmnsny.sbs, kookjar.com, ty54fgd435.my, ue886578433.online, ty4523.space, admin.uipoxy.com, 144.217.243.201, 107.151.248.132, 128.14.210.58) at DNS/firewall/proxy layer
  • Audit DoFun (and other automotive/IoT Android) head units for the com.tw.core (TWCore) package and any unexpected co-installed apps such as com.abc.nexus; remove unauthorized JarService/loader/Zhima payloads
  • Update affected DoFun head units to the vendor-patched TWCore build that disables installNotExists-based unsigned/silent installs

Workarounds

  • Restrict or disable the TWCore app's network and install permissions on fleets where the vendor patch cannot be immediately deployed
  • Segment automotive head-unit/infotainment network paths from other in-vehicle and telematics networks pending remediation

Longer-term hardening

  • Require code-signing verification and installed-package presence checks on every APK pushed through an OEM system app's update channel, MQTT-based or otherwise
  • Deploy network detection for HTTP beaconing to /cpc/api/task and /cpc/api/xml paths and for outbound residential-proxy egress behavior from automotive/IoT device subnets
  • Establish a supply-chain security review process for pre-installed system apps that hold silent-install or update privileges on connected-vehicle infotainment platforms

Weaknesses (CWE) in JarService/Zhima Multi-Stage Android Malware Targets DoFun

CWE-494, CWE-347, CWE-706, CWE-829, CWE-345

Timeline of JarService/Zhima Multi-Stage Android Malware Targets DoFun

  • Earliest identified JarService dropper build staged at http://ovcloudcontrol.cdn.cardoor.cn/upgrade/2024-11-07/fa831c3c23824b99871163387bcda7ad.apk, indicating the campaign's download infrastructure was active by this date.
  • HUMAN Security's Satori team, with Google, Trend Micro and Shadowserver, publicly disclosed and partially disrupted the related BADBOX 2.0 botnet (over 1 million infected consumer/CTV Android devices) -- the malicious platform Kaspersky links the MoYu Group and Zhima activity to.
  • Nokia Deepfield dates a host.dex loader sample (com.xgw.f) tied to the same BADBOX module-loading infrastructure to approximately June 2025, predating public disclosure of the automotive campaign.
  • FBI/IC3 publishes Public Service Announcement I-060525-PSA warning that the BADBOX 2.0 botnet has compromised millions of IoT devices, including aftermarket vehicle infotainment systems.
  • A newer JarService dropper build was staged at http://ovcloudcontrol.cdn.cardoor.cn/upgrade/2025-06-10/fe71af9ecf174de48d2b2ccc2c15fb04.apk.
  • Google files a federal lawsuit against 25 China-based entities allegedly operating the BADBOX 2.0 botnet.
  • Kaspersky researchers discover the JarService/Zhima infection chain targeting DoFun Android automotive head units.
  • Most recent identified JarService build staged at http://ovcloudcontrol.cdn.cardoor.cn/upgrade/2026-06-08/bd80bd3c3d0e4bf6b5b4a825650d01f5.apk, within the window in which Kaspersky researcher Dmitry Kalinin identified the campaign (June 2026).
  • Nokia Deepfield independently verifies the zhima/MoYu Zenlayer- and OVH-hosted C2 infrastructure, including overlap with previously published BADBOX apex domains (ad3g.com, moyu88.xyz, ziyemy.shop).
  • Nokia Deepfield publishes the 'ipmoyu' public research report detailing MoYu/BADBOX 2.0 infrastructure, the zhima proxy module, and the PXYEDGE/ProxyForU resale brands.
  • Kaspersky notifies DoFun of the TWCore MQTT update-validation flaw and the malware campaign; DoFun subsequently reports the issue resolved.
  • Kaspersky publishes the Securelist report 'The invisible passenger in your car,' publicly disclosing the JarService/Zhima campaign, the MoYu Group attribution, and the full IOC set.
  • DoFun confirmed it had fixed the TWCore MQTT update/installNotExists flaw after being notified by Kaspersky, ahead of public disclosure.
  • BleepingComputer, TechNadu, Security Affairs, and CyberInsider report publicly on the Android car head-unit malware campaign, a day after Kaspersky's Securelist publication.

Update history for TL-2026-2111

Sources cited for JarService/Zhima Multi-Stage Android Malware Targets DoFun

Threats related to JarService/Zhima Multi-Stage Android Malware Targets DoFun

Detection coverage for TL-2026-2111

As of 2026-08-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2111 across Splunk SPL, Microsoft KQL and Sigma, covering 92 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats