Find notable cyber news and cases, enriched with sources, timelines, and signals.

DoFun Android head unit malware spread through built-in updaters

Malware Activity
First reported
Last updated
Happening score
H score 31
2 unique sources, 2 articles

Summary

Hide ▲

Kaspersky found a supply-chain attack against Android-based DoFun car head units that used the legitimate TWCore update path to deliver JarService malware. The campaign, attributed to MoYu and linked by Kaspersky to the broader BADBOX ecosystem, installs a hidden payload that reports device data, downloads additional modules, and is used for proxy botnet operations and ad fraud/click fraud. Kaspersky said the malware does not interfere with driving or critical vehicle control systems, and it notified DoFun, which said it resolved the problem.

Related Happenings

Kaspersky endpoint security Windows 14.0.0.504 HardBreacher privilege escalation privilege-escalation flaw

Vulnerability
H score30 First: 03.09.2026 09:26 Last: 03.09.2026 09:26 Sources 1

About this happening: A public HardBreacher PoC exposes a privilege escalation in Kaspersky's endpoint security product for Windows 14.0.0.504, creating local permission-escalation risk and...

COOLCLIENT updated backdoor deploying Msagent.sys

Malware Activity
H score23 First: 24.08.2026 14:51 Last: 24.08.2026 14:51 Sources 1

About this happening: The COOLCLIENT backdoor now deploys a signed kernel-mode driver to hide itself and related artifacts, increasing stealth during active intrusions. The updated variant is t...

MoYu Group campaign expands across multiple victims

Campaign
H score43 First: 21.08.2026 18:41 Last: 21.08.2026 18:41 Sources 1

How related: Despite the efforts of cybersecurity experts and law enforcement agencies to shut down the BADBOX botnet, individual actors associated with it continue their malicious activities, infecting devices worldwide,

About this happening: Kaspersky says a supply-chain attack against Android-based car head units is using the legitimate DoFun update app TWCore to deliver JarService malware, wi...

HelloNet ViPNet update-abuse campaign targeting Russian organizations

Campaign
H score33 First: 19.07.2026 17:23 Last: 19.07.2026 17:23 Sources 1

About this happening: The HelloNet campaign is abusing the ViPNet update mechanism to target Russian organizations, including government agencies, with activity active since at least...

Dragon Boss Solutions LLC adware malicious update

Malware Activity
H score26 First: 16.04.2026 22:07 Last: 16.04.2026 22:07 Sources 1

About this happening: A March 22, 2025 malicious update turned Dragon Boss Solutions LLC adware into an AV-disabling payload, exposing nearly 24,000 systems to follow-on abuse. The upda...

Timeline

  1. 21.08.2026 18:41 3 articles · 13d ago

    DoFun Android head unit malware spread through built-in updaters

    Initial Disclosure

    The infection begins when DoFun head units accept a malicious APK through the legitimate TWCore update mechanism. JarService then starts the loader that pulls the next-stage payload.

    Show sources