Kaspersky: DoFun Android car head units were hit by a MoYu proxy botnet
Kaspersky said a supply-chain infection on DoFun Android car head units used the TWCore updater to install JarService — the first infection chain built specifically for those units. The MoYu group behind BadBox ran MQTT command and control from cardoor.cn.

On August 22 BleepingComputer reported Kaspersky’s findings on a supply-chain infection of DoFun Android car head units. The TWCore updater installed JarService, and Kaspersky said this was the first infection chain built specifically for those units.
What we know
- Kaspersky described a supply-chain infection on DoFun Android car head units in which the TWCore updater installed JarService.
- It was the first infection chain built specifically for those units.
- Kaspersky attributed the campaign to the MoYu group behind BadBox; command and control used MQTT from cardoor.cn.
- The payload ran a zhima reverse proxy and click fraud; driving controls were not targeted.
- DoFun said the problem had been resolved.
Takeaways
- The first-seen chain was built for DoFun Android head units, not a generic phone implant.
- MoYu reused a BadBox-style reverse-proxy and click-fraud playbook over MQTT.
- Kaspersky said driving controls were not the target; DoFun said the issue is resolved.
Source: BleepingComputer / Kaspersky


