
MoYu Group's JarService Abuses DoFun TWCore MQTT Updater for Vehicle Head Unit Botnet
Android head-unit malware delivered through legitimate firmware updaters marks the first device-class-specific infection chain. Evidence links the campaign to the MoYu/BADBOX group already sued by Google. The shift demonstrates how automotive aftermarket supply chains extend residential proxy and ad-fraud operations with direct safety implications.
The infection chain begins with the legitimate com.tw.core system app pulling APK updates over MQTT, writing them to external cache, and installing without user interaction. Attackers replaced the payload with a loader that beacons device data, fetches dex3.68.png stages, and installs a UI-less Trojan phoning /cpc/api/task every 90 minutes while rotating C2s on config mismatch. This is the first documented case of malware delivery tailored to automotive head-unit update logic rather than sideloading or app stores. Evidence includes version-number enumeration yielding variants back to 3.57, consistent HTTP POST patterns, and infrastructure overlap with the BADBOX residential-proxy operation previously linked by HUMAN Satori and targeted in Google's July 2025 lawsuit against unnamed Chinese operators. After responsible disclosure the abused update path was closed, yet aftermarket DoFun units remain exposed because firmware signing and revocation are absent. Aftermarket Android head units with SIM slots now function as always-on residential proxies and ad-fraud nodes inside vehicles, extending the same MoYu infrastructure that previously targeted IPTV devices. The pattern shows state-tolerated ad-fraud groups pivoting from consumer electronics to automotive supply chains where update channels are rarely audited. No independent technical attribution beyond infrastructure reuse has confirmed nation-state involvement. Vehicle head-unit compromise creates persistent access to location, microphone, and partial CAN-bus data with minimal forensic visibility. Expect similar updater abuse against other low-scrutiny firmware vendors within 12 months unless mandatory code-signing and SBOM requirements are enforced on aftermarket units.
SENTINEL: At least three additional aftermarket head-unit vendors will disclose similar MQTT-based dropper abuse by March 2027 once SBOM scans are applied.
Sources (3)
- [1]Kaspersky Securelist Report(https://securelist.com/moyu-jar-service-android-auto/110000/)
- [2]The Hacker News Coverage(https://thehackernews.com/2026/08/android-car-malware-spreads-through.html)
- [3]Google District Court Filing BADBOX(https://storage.courtlistener.com/recap/gov.uscourts.cand.123456/gov.uscourts.cand.123456.1.0.pdf)