"The researchers note that this is the first documented case of a malware infection chain specifically created for the targeted car head unit," Kaspersky researchers wrote.
Supply-chain vector: DoFun's TWCore and cardoor[.]cn
Kaspersky's analysis says the operation began as a supply‑chain attack against Android-based car head units sold by DoFun, a Chinese automotive software, cloud services, and hardware provider owned by Shenzhen Driving Control Technology Co., Ltd. Researchers found a rogue APK being downloaded from a legitimate DoFun system app named TWCore. TWCore receives instructions through an MQTT server hosted at cardoor[.]cn, and the rogue component — a no-interface app Kaspersky calls JarService — arrived via that channel.
JarService infection chain and staged payloads
When JarService runs, Kaspersky reports, it decrypts and executes a second-stage loader that establishes communications with a command-and-control (C2) server and downloads another encrypted payload. The final payload periodically reports device telemetry — including the device model, display resolution, Wi‑Fi SSID, and MAC address — and retrieves attacker-supplied commands.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildMoYu attribution and BadBox ties
Kaspersky attributes the operation to the MoYu group, a threat actor the researchers previously linked to the BadBox malware botnet. The firm says the campaign is notable as the first documented malware infection chain created specifically to target car head units rather than generic Android devices.
zhima reverse-proxy, ad fraud, and command set
According to Kaspersky, the operator primarily loaded a reverse‑proxy module named "zhima" that converts infected head units into proxy botnet nodes. The same activity also included web requests consistent with click‑fraud. Kaspersky lists nine commands the malware supports; as published they are:
- return - Retrieves a specified value from Android’s SharedPreferences storage
- copy - Copies stored or downloaded content to the device clipboard
- http - Sends HTTP GET or POST requests and can save part of the response
- web - Opens a URL in a WebView and executes supplied JavaScript
- loadlib - Not fully implemented when Kaspersky published the report
- loadlib2 - Downloads and executes arbitrary code or additional modules
- loadlib3 - Not fully implemented when Kaspersky published the report
- deeplink - Opens a specified resource in the browser
- traceroute - Checks whether specified hosts are reachable using ICMP ping
Kaspersky notes the presence of modules capable of downloading and running arbitrary code (loadlib2), alongside the reverse‑proxy functionality, which together point to monetization through proxying and advertising fraud rather than vehicle sabotage.
What this means for technologists, DoFun, and end users
- Technologists and security teams: The operation shows a supply‑chain route into embedded Android systems via legitimate update channels (TWCore) and MQTT instruction servers (cardoor[.]cn). Teams will want to monitor for C2‑style connections and indicators tied to the "zhima" module and for unexpected modules downloaded by loadlib2 behavior.
- DoFun and automotive vendors: Kaspersky says it notified DoFun, and the Chinese firm replied that it resolved the problem. Vendors that manage update frameworks or system apps on Android‑based head units should validate update integrity, audit MQTT endpoints, and verify the removal or remediation of rogue APKs.
- End users and drivers: Kaspersky states the malware "does not interfere with driving or critical vehicle control systems" and appears tailored to advertising fraud and proxy monetization. Nevertheless, infected head units reported device identifiers and network details to attackers, a privacy and abuse risk separate from vehicle safety systems.
Kaspersky's disclosure and DoFun's reply close the immediate notification loop, but BleepingComputer says it has contacted the companies with questions about the initial compromise vector and will update its coverage. The technical record in Kaspersky's write‑up — the TWCore download, the MQTT server at cardoor[.]cn, the JarService loader chain, the final telemetry collection, and the zhima reverse‑proxy — leaves a clear trace of how embedded infotainment devices were repurposed for monetization rather than mechanical disruption.
For now, the incident stands as a documented example of how a legitimate device‑update path can be abused to propagate modular malware into in‑vehicle head units, turning infotainment hardware into network infrastructure for attackers' profit.




