First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox Botnet — Threadlinqs Intelligence
As of 2026-08-25, First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox Botnet is a high-severity malware threat attributed to MoYu Group, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-2137 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: MoYu Group · FINANCIAL
Kaspersky identified the first malware family purpose-built for Android-powered aftermarket car head units, abusing a logic flaw in DoFun's TWCore update-handling app to silently install a three-stage
In June 2026, Kaspersky researchers discovered the first documented malware chain built specifically for Android-based aftermarket automotive head units (infotainment systems) manufactured by the Chinese vendor DoFun. The infection abuses a logic flaw in DoFun's legitimate TWCore system app (package com.tw.core), which handles firmware/software updates: an "installNotExists" boolean flag, when set true by the update-distribution side, permits installation of applications that were never originally present on the device, bypassing the intended update-integrity checks. Malicious APK download instructions are pushed to devices over an MQTT message broker hosted on the cardoor[.]cn domain, and the resulting APKs are written to TWCore's external cache directory before silent installation.
The payload is a three-stage chain. Stage 1, "JarService" (package com.tw.jar1), is a silent, UI-less dropper whose code is XOR-encrypted with linearly shifting single-byte keys; its entry point is the wa method of class com.c.j.qbh. Stage 2 is an unnamed loader that beacons device telemetry (userId, dexVersion, channelId, packageName) to the C2 via HTTP POST and receives a download link and decryption parameters (a single-byte key plus a four-byte floating-point XOR value) for Stage 3. Stage 3 is a clicker/loader that reports device fingerprinting data (display resolution, device model, Wi-Fi SSID, MAC address) to /cpc/api/task every 90 minutes and receives productId-mapped JSON task configurations, additionally polling /cpc/api/xml by GET for unknown or outdated commands. Nine C2 commands are implemented (return, copy, http, web, loadlib, loadlib2, loadlib3, deeplink, traceroute); in observed operation only loadlib2 (download-and-execute arbitrary code via reflection) and http were actively used. A dedicated payload module, "zhima," is a reverse-proxy component that enrolls the device as a residential proxy node, registered and monetized through the ProxyForU service (proxyforu[.]com) and managed via an admin panel at admin.uipoxy[.]com.
Kaspersky attributes the campaign to the MoYu Group with high confidence, based on the internal thread name "mosdk-host-loader" referencing MoYu, and on a related dropper (package com.abc.nexus, service AdmoyuService, hash 3AD4BF5A86D26FFBF09CAE42AF330A98) previously found on Android TV set-top boxes tied to the same actor, plus overlapping campaign infrastructure. Nokia's Deepfield Emergency Response Team independently identified the zhima proxy module on set-top boxes, corroborating the residential-proxy-botnet objective. MoYu Group is linked to BADBOX, the large-scale ad-fraud/residential-proxy operation first documented by HUMAN's Satori Threat Intelligence and Research team in October 2023 as a supply-chain compromise deploying Triada malware on budget off-brand Android devices; BadBox 2.0 was reported by Google's 2025 lawsuit to have infected more than 10 million Android-based devices, and Germany's BSI sinkholed roughly 30,000 BadBox-infected devices in December 2024. This campaign represents the first confirmed expansion of BadBox-linked tradecraft into automotive infotainment hardware. DoFun closed the abused update-handling gap after Kaspersky's responsible disclosure. No CVE has been assigned; the vulnerability is a vendor-specific update-authorization logic flaw rather than a memory-safety or classic software vulnerability.
Target sectors: automotive, consumer, advertising technology
Target regions: china, Asia-Pacific
Timeline
- HUMAN's Satori Threat Intelligence and Research team first documents the original BADBOX operation, a supply-chain-based scheme deploying Triada Android malware on budget off-brand devices.
- Earliest identified malicious DoFun head-unit APK build hosted on the cardoor[.]cn update CDN, indicating the campaign was already active over a year before public disclosure.
- Germany's Federal Office for Information Security (BSI) sinkholes DNS for roughly 30,000 BadBox-infected devices, disrupting C2 communications for the original BadBox botnet.
- Google files suit against the anonymous operators of BadBox 2.0, reporting more than 10 million infected Android-based devices tied to the ad-fraud and residential-proxy scheme.
- A second-generation malicious DoFun head-unit APK build appears on the cardoor[.]cn update CDN, showing continued campaign development.
- Kaspersky researchers first identify the DoFun head-unit-targeting malware chain during routine Android threat monitoring.
- Most recent malicious DoFun head-unit APK build identified on the cardoor[.]cn update CDN, shortly before public disclosure.
- Kaspersky publishes its technical analysis, 'First Android malware targeting automotive head units,' on Securelist, following responsible disclosure that led DoFun to close the abused update-handling gap.
- Mainstream security press, including SecurityWeek, reports on Kaspersky's findings, publicizing the first documented malware family purpose-built for automotive Android head units.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1474, T1655, T1407, T1604, T1406, T1422, T1426, T1533, T1544, T1437