# Android Car Head Units Infected by MoYu Proxy Botnet Malware

> A supply-chain attack by MoYu Group uses a legitimate update app to infect Android car head units, forming a proxy botnet for ad fraud.

- Published: 2026-08-22T16:13:49.000Z
- Severity: high
- Category: Supply Chain
- Tags: Android Malware, Proxy Botnet, Supply Chain Attack, Ad Fraud, MoYu Group
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/
- Canonical: https://runtimerebel.com/blog/android-car-head-units-infected-by-moyu-proxy-botnet-malware

## Key points

- Android car head units are infected, forming a proxy botnet and engaging in ad fraud for the MoYu Group.
- Affected systems include DoFun Android-based car head units managed by the TWCore system app.
- Users should check for and apply firmware updates from DoFun or their car manufacturer.

## [Supply Chain Attack](/glossary#supply-chain-attack) Targets Android Car Head Units with MoYu [Malware](/glossary#malware)

Kaspersky researchers have uncovered a novel supply-chain attack leveraging a legitimate device-update application to distribute malware, enrolling compromised Android car head units into a proxy [botnet](/glossary#botnet) or using them for advertising fraud. This operation has been attributed to the MoYu group, a [threat actor](/glossary#threat-actor) previously associated with the BadBox malware botnet. This marks the first documented instance of a malware infection chain specifically engineered for the targeted car head unit ecosystem, highlighting an evolving [threat landscape](/glossary#threat-landscape) in connected vehicles.

The attack primarily targets systems provided by DoFun, a Chinese automotive software and hardware vendor. DoFun supplies generic Android-based head units that serve as command centers for vehicle infotainment, navigation, and settings. While the malware does not interfere with driving or critical vehicle control systems, its presence underscores a significant breach of trust within the automotive supply chain and presents new avenues for attacker monetization, according to [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/).

### Technical Analysis: DoFun TWCore Supply Chain Compromise

The infection chain begins with a rogue APK file downloaded through a legitimate DoFun system app named TWCore. TWCore receives instructions from an MQTT server hosted at cardoor[.]cn. This unidentified application, devoid of any user interface, is a piece of malware dubbed 'JarService'. Upon execution, JarService decrypts and launches a second-stage loader. This loader then establishes communication with a command-and-control ([C2](/glossary#c2)) server to download an additional encrypted [payload](/glossary#payload).

The final payload functions as the core operational component of the botnet. It periodically reports comprehensive device information, including model, display resolution, Wi-Fi SSID, and MAC address, while also retrieving commands from the attackers. The malware supports nine distinct commands, allowing the MoYu group significant control over the compromised devices. Researchers observed that the primary module loaded was 'zhima,' a reverse-proxy module that transforms the infected head unit into a node within a proxy botnet. Furthermore, the malware was noted making web requests consistent with click-fraud activities, indicating its dual purpose for monetization.

This sophisticated approach to compromising a supply chain component like the TWCore app to deploy multi-stage malware demonstrates a targeted and calculated effort by the MoYu group to establish a foothold in a nascent [attack vector](/glossary#attack-vector). Security professionals investigating how to **detect MoYu Group malware on Android head units** should focus on unusual network traffic patterns originating from these devices, particularly connections to unknown C2 infrastructure or ad-fraud related domains.

## Actionable Recommendations for Mitigation

While the immediate impact of this specific malware does not extend to critical vehicle safety, the compromise of a legitimate software update channel for car head units raises serious concerns about the integrity of the automotive supply chain. Defenders must prioritize proactive measures for **mitigation for car infotainment botnets** to prevent similar or more severe future attacks.

### Prioritized Actions:

*   **[Firmware](/glossary#firmware) Updates**: The most crucial step for affected individuals is to check for and promptly apply any available firmware updates or patches from DoFun or their specific car manufacturer. Kaspersky states they notified DoFun, and the company indicated the problem was resolved, suggesting a [patch](/glossary#patch) may be available.
*   **Network Monitoring**: For organizations managing fleets or with sufficient technical capabilities, monitor network traffic originating from car head units. Look for suspicious connections to unusual IP addresses or domains, especially those related to proxy services or known malicious C2 infrastructure.
*   **Supply Chain Vigilance**: Automotive OEMs and software providers must enhance their supply chain security protocols. This includes rigorous vetting of third-party software, regular security audits of update mechanisms, and implementing strong code signing practices to prevent unauthorized modifications to legitimate applications like TWCore.
*   **User Awareness**: While difficult for end-users to detect this type of sophisticated supply chain attack, general best practices around purchasing devices from trusted sources and being wary of unofficial updates remain relevant.

**Related:** [Popa Botnet Linked to Alarum Technologies’ NetNut Proxy Service](/blog/popa-botnet-linked-to-alarum-technologies-netnut-proxy-service), [npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises](/blog/npm-supply-chain-attacks-shai-hulud-miasma-and-ci-cd-compromises)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/android-car-head-units-infected-by-moyu-proxy-botnet-malware
