logo

The invisible passenger in your car

ID: c9fda0f3-8eef-54d9-add4-852511c62432

STIX ID: report--c9fda0f3-8eef-54d9-add4-852511c62432

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: Dmitry Kalinin

...
...

This report describes the June 2026 discovery of a novel multi-stage Android malware campaign that leverages the built-in updater of Android-based automotive head units (TWCore) to silently install a UI-less dropper (JarService) which retrieves staged loaders and a zhima reverse-proxy module used for ad fraud and building a proxy botnet; the activity is attributed with high confidence to the MoYu Group (BADBOX) and includes detailed TTPs, C2 examples, hashes, domains, IPs, download URLs, and notes that the vendor remedied the distribution mechanism.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.