logo

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

ID: db1b346f-3b0c-5402-b786-c03f3cc70f8b

STIX ID: report--db1b346f-3b0c-5402-b786-c03f3cc70f8b

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-08-21

Date Updated: 2026-08-22

Author: [email protected] (The Hacker News)

...
...

Kaspersky researchers uncovered a multi-stage malware campaign targeting DoFun Android automotive head units by weaponizing the legitimate TWCore updater to deploy a dropper (JarService) and downloader that installs a background-only app used for ad fraud and to create a proxy botnet; the activity is attributed to the MoYu Group linked to BADBOX, includes identifiable C2 endpoints and commands, and was mitigated after responsible disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.