DoFun Android head unit malware spread through built-in updaters
Malware Activity
Summary
Hide ▲
Show ▼
Kaspersky found a supply-chain attack against Android-based DoFun car head units that used the legitimate TWCore update path to deliver JarService malware. The campaign, attributed to MoYu and linked by Kaspersky to the broader BADBOX ecosystem, installs a hidden payload that reports device data, downloads additional modules, and is used for proxy botnet operations and ad fraud/click fraud. Kaspersky said the malware does not interfere with driving or critical vehicle control systems, and it notified DoFun, which said it resolved the problem.
Related Happenings
Kaspersky endpoint security Windows 14.0.0.504 HardBreacher privilege escalation privilege-escalation flaw
Vulnerability
H score30
First: 03.09.2026 09:26
Last: 03.09.2026 09:26
Sources 1
About this happening:
A public HardBreacher PoC exposes a privilege escalation in Kaspersky's endpoint security product for Windows 14.0.0.504, creating local permission-escalation risk and...
Kaspersky endpoint security Windows 14.0.0.504 HardBreacher privilege escalation privilege-escalation flaw
VulnerabilityAbout this happening: A public HardBreacher PoC exposes a privilege escalation in Kaspersky's endpoint security product for Windows 14.0.0.504, creating local permission-escalation risk and...
COOLCLIENT updated backdoor deploying Msagent.sys
Malware Activity
H score23
First: 24.08.2026 14:51
Last: 24.08.2026 14:51
Sources 1
About this happening:
The COOLCLIENT backdoor now deploys a signed kernel-mode driver to hide itself and related artifacts, increasing stealth during active intrusions. The updated variant is t...
COOLCLIENT updated backdoor deploying Msagent.sys
Malware ActivityAbout this happening: The COOLCLIENT backdoor now deploys a signed kernel-mode driver to hide itself and related artifacts, increasing stealth during active intrusions. The updated variant is t...
MoYu Group campaign expands across multiple victims
Campaign
H score43
First: 21.08.2026 18:41
Last: 21.08.2026 18:41
Sources 1
How related:
Despite the efforts of cybersecurity experts and law enforcement agencies to shut down the BADBOX botnet, individual actors associated with it continue their malicious activities, infecting devices worldwide,
About this happening:
Kaspersky says a supply-chain attack against Android-based car head units is using the legitimate DoFun update app TWCore to deliver JarService malware, wi...
MoYu Group campaign expands across multiple victims
CampaignHow related: Despite the efforts of cybersecurity experts and law enforcement agencies to shut down the BADBOX botnet, individual actors associated with it continue their malicious activities, infecting devices worldwide,
About this happening: Kaspersky says a supply-chain attack against Android-based car head units is using the legitimate DoFun update app TWCore to deliver JarService malware, wi...
HelloNet ViPNet update-abuse campaign targeting Russian organizations
Campaign
H score33
First: 19.07.2026 17:23
Last: 19.07.2026 17:23
Sources 1
About this happening:
The HelloNet campaign is abusing the ViPNet update mechanism to target Russian organizations, including government agencies, with activity active since at least...
HelloNet ViPNet update-abuse campaign targeting Russian organizations
CampaignAbout this happening: The HelloNet campaign is abusing the ViPNet update mechanism to target Russian organizations, including government agencies, with activity active since at least...
Dragon Boss Solutions LLC adware malicious update
Malware Activity
H score26
First: 16.04.2026 22:07
Last: 16.04.2026 22:07
Sources 1
About this happening:
A March 22, 2025 malicious update turned Dragon Boss Solutions LLC adware into an AV-disabling payload, exposing nearly 24,000 systems to follow-on abuse. The upda...
Dragon Boss Solutions LLC adware malicious update
Malware ActivityAbout this happening: A March 22, 2025 malicious update turned Dragon Boss Solutions LLC adware into an AV-disabling payload, exposing nearly 24,000 systems to follow-on abuse. The upda...
Timeline
-
21.08.2026 18:41 3 articles · 13d ago
DoFun Android head unit malware spread through built-in updaters
Initial DisclosureThe infection begins when DoFun head units accept a malicious APK through the legitimate TWCore update mechanism. JarService then starts the loader that pulls the next-stage payload.
Show sources
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet — thehackernews.com — 21.08.2026 18:41
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet — thehackernews.com — 21.08.2026 18:41
- Hackers infect Android car head units with proxy botnet malware — www.bleepingcomputer.com — 22.08.2026 17:14