Particle.news

Malware Uses DoFun Updater to Turn Android Car Head Units Into Proxy Botnet

Kaspersky says attackers weaponized the TWCore update channel to install a dropper that fetches ad‑fraud and reverse‑proxy modules, exposing widely used infotainment systems to large‑scale abuse.

Overview

  • Kaspersky discovered in June 2026 that attackers abused TWCore, DoFun’s built‑in updater, to install a silent dropper called JarService on Android car head units.
  • JarService decrypts and launches a downloader that posts device details to command‑and‑control servers and retrieves staged payloads including a clicker for ad fraud and the 'zhima' reverse‑proxy module.
  • The operation is tied to the BADBOX ecosystem and attributed with high confidence to the MoYu Group, with links to residential proxy services such as PXYEDGE and ProxyForU.
  • DoFun was notified by Kaspersky and has addressed the insecure update distribution; observed impacts so far include slower infotainment performance and reduced network speed with risk that operators could push further malicious modules.
  • The case shows how Android‑based head units with cellular or Wi‑Fi access and SIM slots can be repurposed at scale, underscoring the need for authenticated update channels, supply‑chain checks, and stronger vendor incident response.