DoFun Android head unit malware spread through built-in updaters
Malware Activity
Summary
Hide ▲
Show ▼
A new Android head-unit malware spread through built-in updaters on DoFun firmware, enabling ad fraud, unwanted ads, and proxy botnet activity on infected devices. The infection chain uses the legitimate TWCore update path and JarService to install a hidden payload. The malware checks in to C2 every 90 minutes and can fetch additional modules such as zhima. The activity was tied with high confidence to MoYu Group and the broader BADBOX ecosystem.
Related Happenings
MoYu Group campaign expands across multiple victims
Campaign
H score38
First: 21.08.2026 18:41
Last: 21.08.2026 18:41
Sources 1
How related:
Despite the efforts of cybersecurity experts and law enforcement agencies to shut down the BADBOX botnet, individual actors associated with it continue their malicious activities, infecting devices worldwide,
About this happening:
The BADBOX infection campaign is still active, with MoYu Group-linked actors using abused update channels to spread malware to devices worldwide and support ad fraud...
MoYu Group campaign expands across multiple victims
CampaignHow related: Despite the efforts of cybersecurity experts and law enforcement agencies to shut down the BADBOX botnet, individual actors associated with it continue their malicious activities, infecting devices worldwide,
About this happening: The BADBOX infection campaign is still active, with MoYu Group-linked actors using abused update channels to spread malware to devices worldwide and support ad fraud...
Dragon Boss Solutions LLC adware malicious update
Malware Activity
H score26
First: 16.04.2026 22:07
Last: 16.04.2026 22:07
Sources 1
About this happening:
A March 22, 2025 malicious update turned Dragon Boss Solutions LLC adware into an AV-disabling payload, exposing nearly 24,000 systems to follow-on abuse. The upda...
Dragon Boss Solutions LLC adware malicious update
Malware ActivityAbout this happening: A March 22, 2025 malicious update turned Dragon Boss Solutions LLC adware into an AV-disabling payload, exposing nearly 24,000 systems to follow-on abuse. The upda...
BeatBanker Android malware activity
Malware Activity
H score26
First: 10.03.2026 23:27
Last: 10.03.2026 23:27
Sources 1
About this happening:
The BeatBanker Android malware is actively hijacking devices by posing as a Starlink app, creating risk of credential theft, illicit mining, and remote device control....
BeatBanker Android malware activity
Malware ActivityAbout this happening: The BeatBanker Android malware is actively hijacking devices by posing as a Starlink app, creating risk of credential theft, illicit mining, and remote device control....
Keenadu Android backdoor embedded in firmware and app delivery paths
Malware Activity
H score27
First: 17.02.2026 16:05
Last: 17.02.2026 16:05
Sources 1
About this happening:
The Keenadu Android backdoor was found embedded in firmware from multiple device brands, putting infected devices and their installed apps at risk of full compromise. The...
Keenadu Android backdoor embedded in firmware and app delivery paths
Malware ActivityAbout this happening: The Keenadu Android backdoor was found embedded in firmware from multiple device brands, putting infected devices and their installed apps at risk of full compromise. The...
Timeline
-
21.08.2026 18:41 2 articles · 3h ago
DoFun Android head unit malware spread through built-in updaters
Initial DisclosureThe infection begins when DoFun head units accept a malicious APK through the legitimate TWCore update mechanism. JarService then starts the loader that pulls the next-stage payload.
Show sources
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet — thehackernews.com — 21.08.2026 18:41
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet — thehackernews.com — 21.08.2026 18:41