JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet
JarService/Zhima Multi-Stage Android Malware Targets DoFun (TL-2026-2111) is a high-severity malware campaign, first published 2026-08-22 and last reviewed 2026-08-23. It is attributed to MoYu Group with high confidence, affects DoFun DoFun Android automotive head units (TWCore system app, package, maps to 24 MITRE ATT&CK techniques (T1027, T1059.007, T1071.001), and is covered by 9 detection rules and 92 indicators of compromise.
Key facts for TL-2026-2111
- Threat ID
- TL-2026-2111
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-08-22
- Last reviewed
- 2026-08-23
- Attribution
- MoYu Group
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- automotive, consumer, advertising
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 92
- Updates
- 2026-08-23 · revalidated 1× · latest source
Malware and tooling in JarService/Zhima Multi-Stage Android Malware Targets DoFun
Malware and tooling: BadBox, JarService, Zhima
Kaspersky documented the first known Android malware campaign targeting automotive head units: a three-stage infection chain (JarService dropper -> loader -> Zhima reverse-proxy module) delivered by abusing the legitimate DoFun TWCore system app's MQTT-based update mechanism. Attributed with high confidence to the MoYu Group and linked to the BADBOX botnet platform, the malware turns infected head units into ad-fraud clickers and residential-proxy nodes.
How JarService/Zhima Multi-Stage Android Malware Targets DoFun works
In August 2026, Kaspersky researcher Dmitry Kalinin published Securelist analysis of the first documented Android malware family built specifically to compromise automotive infotainment ("head unit") systems. The victim platform is DoFun, an Android-based automotive head-unit vendor that Kaspersky states serves over 30 million vehicle owners globally. The infection vector abuses TWCore (package `com.tw.core`), a legitimate, pre-installed DoFun system application responsible for analytics and OTA software updates. TWCore receives update instructions over an MQTT message broker hosted at `cardoor.cn`, and Kaspersky found that when the broker's `installNotExists` flag is set to `true`, TWCore will silently install an APK without first checking whether it is already present on the device and without validating any code-signing signature on the downloaded package. Attackers abused this design flaw to push a malicious APK, JarService, from `ovcloudcontrol.cdn.cardoor.cn`, with build artifacts observed dating back to at least November 2024 and as recently as June 2026.
JarService is a headless, UI-less dropper (entry class `com.c.j.qbh`, method `wa`) that stores its payload as XOR-encrypted code blocks using a linearly shifting single-byte key, and decrypts/launches an intermediate loader (entry point `com.ast.sdk.BillingMain`, method `init`; at least 7 distinct versions observed, 3.57-3.680). The loader beacons device and version metadata (userId, dexVersion, dexType, channelId, packageName, appVersion, appName) to attacker infrastructure over HTTP POST and receives a `dexUrl` pointing to the stage-3 payload, which it decrypts using a single-byte key combined with a four-byte floating-point XOR value. Stage 3 is a clicker/reverse-proxy loader that checks in roughly every 90 minutes (5,500,000 ms) against a `/cpc/api/task` endpoint for configuration (observed configVersion 3.82) and retrieves executable command scripts via `/cpc/api/xml`. The framework implements nine remote commands mapped to individual classes, including `return` (read SharedPreferences), `copy` (clipboard manipulation), `http` (arbitrary HTTP request/response parsing used for ad-fraud and HTTP manipulation), `web` (WebView injection executing arbitrary attacker-supplied JavaScript), `loadlib2` (download and reflectively execute additional Dex code, MD5-verified), `deeplink` (forced browser redirection), and `traceroute` (ICMP reachability probing).
The `loadlib2` command is primarily used to install Zhima, a reverse-proxy module (8 sample variants identified, earliest labeled version 57) that converts the infected head unit into a residential-proxy node, routing third-party traffic through the vehicle's internet connection for monetization. Zhima is administered through a panel at `admin.uipoxy.com/proxy/u/login`, configured with proxy ports 1002, 1337, 7777, 8888, and 15000. Kaspersky attributes the campaign with high confidence to the MoYu Group based on internal thread-naming artifacts ("mosdk-host-loader", where mosdk = MoYu SDK), a related malicious package (`com.abc.nexus`) previously seen on Android TV set-top boxes, a shared service name (`AdmoyuService`) in parallel infrastructure, and network-infrastructure overlap with known MoYu Group C2s. The MoYu Group is separately linked to the BADBOX malicious-platform ecosystem (the Triada-based backdoor family disrupted in its "BADBOX 2.0" form by HUMAN Security, Google, Trend Micro and Shadowserver in March 2025 across more than a million consumer Android/CTV devices), and Kaspersky found the Zhima admin panel's design and copyright strings overlap with the residential-proxy resale services ProxyForU and PXYEDGE, which share the same `/proxy/u/login` authentication API pattern. Nokia's Deepfield Emergency Response Team independently and concurrently identified the Zhima family operating on Android TV set-top boxes, corroborating that the broader operation spans multiple device classes beyond automotive head units. Kaspersky notified DoFun of the distribution scheme prior to publication, and DoFun subsequently confirmed it fixed the underlying TWCore issue. No CVE has been assigned to the `installNotExists` design flaw.
MITRE ATT&CK techniques used in TL-2026-2111
Defense Evasion
T1027 Obfuscated Files or Information; T1406 Obfuscated Files or Information; T1407 Download New Code at Runtime; T1604 Proxy Through Victim; T1620 Reflective Code Loading
Execution
T1059.007 JavaScript; T1623 Command and Scripting Interpreter
Command and Control
T1071.001 Web Protocols; T1090.002 External Proxy; T1437 Application Layer Protocol; T1481 Web Service
Discovery
T1082 System Information Discovery; T1421 System Network Connections Discovery; T1422 System Network Configuration Discovery; T1426 System Information Discovery
Initial Access
T1195.002 Compromise Software Supply Chain; T1474 Supply Chain Compromise
Collection
Impact
T1496.002 Bandwidth Hijacking; T1565.002 Transmitted Data Manipulation; T1643 Generate Traffic from Victim
Persistence
T1577 Compromise Application Executable
Resource Development
Affected products and versions in JarService/Zhima Multi-Stage Android Malware Targets DoFun
- DoFun — DoFun Android automotive head units (TWCore system app, package com.tw.core)
Vulnerable versions: TWCore builds with installNotExists=true and no APK signature validation, prior to vendor remediation
Fixed in: TWCore build patched by DoFun after Kaspersky notification, confirmed prior to 2026-08-21
Remediation for JarService/Zhima Multi-Stage Android Malware Targets DoFun
Patches
- DoFun vendor fix for the TWCore installNotExists design flaw, deployed after Kaspersky's disclosure and confirmed prior to the August 21, 2026 Securelist publication
Immediate actions
- Block the listed JarService/Zhima C2 domains and IPs (cardoor.cn, xmsae.sbs, ishano456.sbs, xshaon123.sbs, kshahnd.sbs, mdsjhd.sbs, nmnsny.sbs, kookjar.com, ty54fgd435.my, ue886578433.online, ty4523.space, admin.uipoxy.com, 144.217.243.201, 107.151.248.132, 128.14.210.58) at DNS/firewall/proxy layer
- Audit DoFun (and other automotive/IoT Android) head units for the com.tw.core (TWCore) package and any unexpected co-installed apps such as com.abc.nexus; remove unauthorized JarService/loader/Zhima payloads
- Update affected DoFun head units to the vendor-patched TWCore build that disables installNotExists-based unsigned/silent installs
Workarounds
- Restrict or disable the TWCore app's network and install permissions on fleets where the vendor patch cannot be immediately deployed
- Segment automotive head-unit/infotainment network paths from other in-vehicle and telematics networks pending remediation
Longer-term hardening
- Require code-signing verification and installed-package presence checks on every APK pushed through an OEM system app's update channel, MQTT-based or otherwise
- Deploy network detection for HTTP beaconing to /cpc/api/task and /cpc/api/xml paths and for outbound residential-proxy egress behavior from automotive/IoT device subnets
- Establish a supply-chain security review process for pre-installed system apps that hold silent-install or update privileges on connected-vehicle infotainment platforms
Weaknesses (CWE) in JarService/Zhima Multi-Stage Android Malware Targets DoFun
CWE-494, CWE-347, CWE-706, CWE-829, CWE-345
Timeline of JarService/Zhima Multi-Stage Android Malware Targets DoFun
- Earliest identified JarService dropper build staged at http://ovcloudcontrol.cdn.cardoor.cn/upgrade/2024-11-07/fa831c3c23824b99871163387bcda7ad.apk, indicating the campaign's download infrastructure was active by this date.
- HUMAN Security's Satori team, with Google, Trend Micro and Shadowserver, publicly disclosed and partially disrupted the related BADBOX 2.0 botnet (over 1 million infected consumer/CTV Android devices) -- the malicious platform Kaspersky links the MoYu Group and Zhima activity to.
- Nokia Deepfield dates a host.dex loader sample (com.xgw.f) tied to the same BADBOX module-loading infrastructure to approximately June 2025, predating public disclosure of the automotive campaign.
- FBI/IC3 publishes Public Service Announcement I-060525-PSA warning that the BADBOX 2.0 botnet has compromised millions of IoT devices, including aftermarket vehicle infotainment systems.
- A newer JarService dropper build was staged at http://ovcloudcontrol.cdn.cardoor.cn/upgrade/2025-06-10/fe71af9ecf174de48d2b2ccc2c15fb04.apk.
- Google files a federal lawsuit against 25 China-based entities allegedly operating the BADBOX 2.0 botnet.
- Kaspersky researchers discover the JarService/Zhima infection chain targeting DoFun Android automotive head units.
- Most recent identified JarService build staged at http://ovcloudcontrol.cdn.cardoor.cn/upgrade/2026-06-08/bd80bd3c3d0e4bf6b5b4a825650d01f5.apk, within the window in which Kaspersky researcher Dmitry Kalinin identified the campaign (June 2026).
- Nokia Deepfield independently verifies the zhima/MoYu Zenlayer- and OVH-hosted C2 infrastructure, including overlap with previously published BADBOX apex domains (ad3g.com, moyu88.xyz, ziyemy.shop).
- Nokia Deepfield publishes the 'ipmoyu' public research report detailing MoYu/BADBOX 2.0 infrastructure, the zhima proxy module, and the PXYEDGE/ProxyForU resale brands.
- Kaspersky notifies DoFun of the TWCore MQTT update-validation flaw and the malware campaign; DoFun subsequently reports the issue resolved.
- Kaspersky publishes the Securelist report 'The invisible passenger in your car,' publicly disclosing the JarService/Zhima campaign, the MoYu Group attribution, and the full IOC set.
- DoFun confirmed it had fixed the TWCore MQTT update/installNotExists flaw after being notified by Kaspersky, ahead of public disclosure.
- BleepingComputer, TechNadu, Security Affairs, and CyberInsider report publicly on the Android car head-unit malware campaign, a day after Kaspersky's Securelist publication.
Update history for TL-2026-2111
- 2026-08-23 — MoYu Group Infects DoFun Android Car Head Units via TWCore MQTT Backdoor with JarService/Zhima Proxy Botnet Malware (BADBOX-Linked): What changed No escalation to core fields: the trigger report independently corroborates severity (HIGH), exploitability (ACTIVE), status (ACTIVE), threat_actor (MoYu Group), and motivation (FINANCIAL). Its own attribution_confidence (MEDIU
Sources cited for JarService/Zhima Multi-Stage Android Malware Targets DoFun
- The invisible passenger in your car: First Android malware targeting automotive head units
- Malware in car infotainment systems: how infection occurs
- BadBox-linked Android malware has now infected car head units
- Satori Threat Intelligence Disruption: BADBOX 2.0 Targets Consumer Devices with Multiple Fraud Schemes
- BADBOX 2.0 Botnet Infects 1 Million Android Devices for Ad Fraud and Proxy Abuse
- Badbox Android botnet disrupted through coordinated threat hunting
- Home Internet Connected Devices Facilitate Criminal Activity (residential proxy network warning)
Threats related to JarService/Zhima Multi-Stage Android Malware Targets DoFun
- First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox Botnet
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
- Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise: Sideloading, SMS Phishing, and Trojanized Updates as Android Distribution Vectors
- Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service
Detection coverage for TL-2026-2111
As of 2026-08-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2111 across Splunk SPL, Microsoft KQL and Sigma, covering 92 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.