Overview
- Kaspersky discovered in June 2026 that attackers abused TWCore, DoFun’s built‑in updater, to install a silent dropper called JarService on Android car head units.
- JarService decrypts and launches a downloader that posts device details to command‑and‑control servers and retrieves staged payloads including a clicker for ad fraud and the 'zhima' reverse‑proxy module.
- The operation is tied to the BADBOX ecosystem and attributed with high confidence to the MoYu Group, with links to residential proxy services such as PXYEDGE and ProxyForU.
- DoFun was notified by Kaspersky and has addressed the insecure update distribution; observed impacts so far include slower infotainment performance and reduced network speed with risk that operators could push further malicious modules.
- The case shows how Android‑based head units with cellular or Wi‑Fi access and SIM slots can be repurposed at scale, underscoring the need for authenticated update channels, supply‑chain checks, and stronger vendor incident response.