
DoFun Android head units compromised via TWCore to deploy JarService reverse proxies in MoYu-linked botnet
Android head units from DoFun were turned into botnet nodes via abuse of their built-in TWCore update app. The campaign extends the BadBox lineage despite prior takedowns and matches FBI warnings on infotainment targeting. Supply chain weaknesses in Chinese automotive software enable undetected proxy deployment for traffic anonymization.
The infection chain begins with TWCore, a preinstalled system component on DoFun devices that handles updates and analytics. Attackers abused its download capability to sideload JarService, which then fetches additional modules including a reverse proxy that routes external traffic through the vehicle's cellular connection. This marks the first publicly detailed case of malware specifically engineered for automotive head units rather than relying on physical access or OS exploits.
Technical indicators align with prior BadBox operations tracked by HUMAN Security in 2023, where over 70,000 Android devices shipped pre-infected from Chinese manufacturers. German authorities severed the original BadBox C2 in December 2024, yet the actors resurfaced with updated infrastructure. The FBI alert from 2024 explicitly flagged aftermarket infotainment systems as targets, confirming the shift from consumer gadgets to automotive endpoints.
Official attribution to MoYu Group rests on code reuse and infrastructure patterns reported by Kaspersky, yet independent verification of direct command-and-control links remains limited to behavioral matches. This supply-chain vector exposes a gap in automotive software procurement: vendors like DoFun integrate third-party analytics without sufficient integrity checks, allowing persistent botnet recruitment even after law enforcement disruptions.
Next steps include expanded scanning of DoFun firmware variants and monitoring for proxy traffic originating from vehicle IP ranges. Similar abuse of update mechanisms is likely in other Chinese automotive suppliers lacking signed update enforcement.
Kaspersky: JarService detections on additional DoFun head unit models will exceed 2,000 unique devices within 120 days.
Sources (2)
- [1]Primary Source(https://therecord.media/android-botnet-china-hackers)
- [2]Supporting Source(https://www.ic3.gov/Media/News/2024/2407xx.pdf)