MoYu Group campaign expands across multiple victims
Campaign
Summary
Hide ▲
Show ▼
Kaspersky says a supply-chain attack against Android-based car head units is using the legitimate DoFun update app TWCore to deliver JarService malware, with the activity attributed to MoYu and linked to the broader BADBOX ecosystem. The malware chain uses a C2 server and a second-stage loader to install payloads, then turns compromised devices into proxy botnet nodes and supports ad fraud/click fraud. Kaspersky says the malware does not affect driving or critical vehicle controls, and the campaign is described as the first documented infection chain built specifically for the targeted car head unit.
Related Happenings
Ted Linux implant in trojanized HAProxy load balancers
Malware Activity
H score22
First: 04.09.2026 17:51
Last: 04.09.2026 17:51
Sources 1
About this happening:
The newly identified ted Linux implant was compiled into trojanized HAProxy load balancers, giving operators a way to intercept web traffic and serve altered pages...
Ted Linux implant in trojanized HAProxy load balancers
Malware ActivityAbout this happening: The newly identified ted Linux implant was compiled into trojanized HAProxy load balancers, giving operators a way to intercept web traffic and serve altered pages...
DoFun Android head unit malware spread through built-in updaters
Malware Activity
H score31
First: 21.08.2026 18:41
Last: 21.08.2026 18:41
Sources 1
How related:
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud.
About this happening:
Kaspersky found a supply-chain attack against Android-based DoFun car head units that used the legitimate TWCore update path to deliver JarService malware. The...
DoFun Android head unit malware spread through built-in updaters
Malware ActivityHow related: A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud.
About this happening: Kaspersky found a supply-chain attack against Android-based DoFun car head units that used the legitimate TWCore update path to deliver JarService malware. The...
HoneyMyte PlugX campaign targeting Myanmar
Campaign
H score32
First: 14.08.2026 16:08
Last: 14.08.2026 16:08
Sources 1
About this happening:
The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity...
HoneyMyte PlugX campaign targeting Myanmar
CampaignAbout this happening: The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
Keenadu Android backdoor embedded in firmware and app delivery paths
Malware Activity
H score27
First: 17.02.2026 16:05
Last: 17.02.2026 16:05
Sources 1
About this happening:
The Keenadu Android backdoor was found embedded in firmware from multiple device brands, putting infected devices and their installed apps at risk of full compromise. The...
Keenadu Android backdoor embedded in firmware and app delivery paths
Malware ActivityAbout this happening: The Keenadu Android backdoor was found embedded in firmware from multiple device brands, putting infected devices and their installed apps at risk of full compromise. The...
Timeline
-
21.08.2026 18:41 3 articles · 13d ago
Kaspersky identifies Android malware on DoFun head unit firmware
Initial DisclosureKaspersky identifies a new Android malware family targeting DoFun vehicle head unit firmware, first discovered in June 2026, and attributes the activity with high confidence to MoYu Group and the broader BADBOX operation. The malware abuses built-in updater functionality in Android-based automotive head units, uses the TWCore update path and the JarService dropper to stage additional payloads, and is designed to support ad fraud and proxy-botnet activity.
Show sources
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet — thehackernews.com — 21.08.2026 18:41
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet — thehackernews.com — 21.08.2026 18:41
- Hackers infect Android car head units with proxy botnet malware — www.bleepingcomputer.com — 22.08.2026 17:14