Overview
- Kaspersky published a technical analysis that traces a June 2026 infection chain using DoFun’s TWCore updater to silently install a dropper called JarService on Android head units.
- The updater was driven by MQTT messages from a broker at cardoor[.]cn and used an installNotExists flag to push APKs into the head unit cache for automatic installation.
- JarService launches a downloader that checks in with a command server every 90 minutes and can fetch modules such as a clicker for ad fraud and the zhima reverse-proxy that turns units into residential proxy nodes.
- Researchers link the campaign to the BADBOX ecosystem and the MoYu Group and found ties between the botnet infrastructure and commercial proxy services PXYEDGE and ProxyForU.
- Kaspersky says DoFun was notified and the update-distribution behavior was addressed, but the case highlights persistent supply-chain risks as BADBOX actors shift to new device classes and infected units can degrade infotainment performance without affecting vehicle control.