A Poisoned Update Channel
The campaign targets head units running software from DoFun, a Chinese automotive software provider that says it serves more than 30 million vehicle owners. Attackers hijacked TWCore, the legitimate system app that updates DoFun head units, and used it to push a hidden malware dropper called JarService directly onto devices.
The malware installs like an ordinary app but has no interface at all, running unnoticed in the background. It then downloads encrypted payloads that report device details and await commands, including one that loads a reverse-proxy module named "zhima," turning the car's screen into a node in a for-rent proxy network.
Who Is Behind It
Kaspersky attributes the operation to the MoYu Group, a threat actor tied to BadBox, the notorious botnet built from cheap infected Android TV boxes and tablets. Cars appear to be the botnet's newest frontier.
There is one reassurance: the malware does not touch driving or critical vehicle controls, researchers say. Its goal is money, not mayhem — click fraud and selling access to the hijacked internet connections. Kaspersky notified DoFun, and the company says the problem has been resolved.
What Comes Next
The precedent matters more than this single campaign. Head units are internet-connected computers that owners rarely think of as hackable, and update channels reach millions of them at once. Researchers have not yet said how DoFun's update pipeline was compromised, an answer that will determine whether other automotive software vendors face the same exposure.
Frequently Asked Questions
- Can this car malware affect driving safety?
- No. Kaspersky says the malware does not interfere with driving or critical vehicle systems. It abuses the head unit's internet connection for ad fraud and proxy services.
- Which cars are affected?
- Vehicles with Android head units running software from DoFun, a Chinese provider that says it serves over 30 million vehicle owners. DoFun says the issue has been resolved.
- Why is this attack significant?
- It is the first documented malware infection chain built specifically for car head units, extending the BadBox-style botnet model from TV boxes to vehicles.

