Particle.news

Malware Used DoFun Updater to Infect Android Car Head Units

Kaspersky’s report shows a built-in update channel was abused to turn infotainment systems into proxy nodes that siphon bandwidth for ad fraud.

Overview

  • Kaspersky published a technical analysis that traces a June 2026 infection chain using DoFun’s TWCore updater to silently install a dropper called JarService on Android head units.
  • The updater was driven by MQTT messages from a broker at cardoor[.]cn and used an installNotExists flag to push APKs into the head unit cache for automatic installation.
  • JarService launches a downloader that checks in with a command server every 90 minutes and can fetch modules such as a clicker for ad fraud and the zhima reverse-proxy that turns units into residential proxy nodes.
  • Researchers link the campaign to the BADBOX ecosystem and the MoYu Group and found ties between the botnet infrastructure and commercial proxy services PXYEDGE and ProxyForU.
  • Kaspersky says DoFun was notified and the update-distribution behavior was addressed, but the case highlights persistent supply-chain risks as BADBOX actors shift to new device classes and infected units can degrade infotainment performance without affecting vehicle control.