Overview
- Kaspersky published technical findings in late August showing attackers used the TWCore system updater and its message broker to push malicious APKs to DoFun firmware on Android head units.
- The infection runs in three stages: a JarService dropper, a loader that gathers device info, and a periodic check-in stage that downloads a reverse-proxy module called zhima.
- The malware uses TWCore’s installNotExists flag to install apps silently, and observed payloads perform background ad-fraud and proxy traffic routing without affecting vehicle driving systems.
- Kaspersky links the operation with high confidence to the MoYu Group and the BADBOX ecosystem, and Nokia’s Deepfield team found the same zhima module on TV set-top boxes, suggesting a cross-device campaign.
- DoFun says it has patched the vulnerable update channel after responsible disclosure, but researchers warn the full scope and whether other head-unit vendors are affected remain unclear and hard for owners to verify.