Executive Summary
In August 2026, Kaspersky researchers discovered a sophisticated supply-chain attack by the MoYu threat group targeting Android-based car head units manufactured by DoFun, a Chinese automotive software provider. The attackers compromised the legitimate TWCore system app to deliver JarService malware, which established command-and-control communication and downloaded additional payloads. The malware transformed infected head units into proxy botnet nodes and conducted advertising fraud operations, marking the first documented malware infection chain specifically designed for automotive head units. While the malware did not interfere with critical vehicle systems, it demonstrated a new attack vector in the expanding Internet of Things landscape.
This incident highlights the growing security risks in connected vehicle ecosystems as automotive manufacturers increasingly integrate internet-connected Android systems. The attack underscores vulnerabilities in automotive supply chains and the emergence of vehicles as new targets for cybercriminal monetization schemes.
Why This Matters Now
Connected vehicles represent a rapidly expanding attack surface as automotive manufacturers integrate more internet-enabled systems, creating new opportunities for cybercriminals to exploit automotive supply chains and establish persistent botnets in mobile environments.
Attack Path Analysis
The MoYu group conducted a supply-chain attack against Android car head units by compromising the legitimate DoFun TWCore system app to deliver JarService malware via MQTT communications. The malware established C2 communication, downloaded encrypted payloads, and executed proxy botnet operations while collecting device information. The compromised head units were enrolled as residential proxy nodes and used for advertising fraud, with no impact to critical vehicle systems.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers compromised the DoFun TWCore system app through supply-chain infiltration, causing it to download and install a rogue APK (JarService malware) via MQTT server communications from cardoor[.]cn
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Supply Chain
User Execution: Malicious File
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Deobfuscate/Decode Files or Information
Application Layer Protocol: Web Protocols
Proxy: Multi-hop Proxy
Data Manipulation: Stored Data Manipulation
Acquire Infrastructure: Virtual Private Server
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-161 Rev 1 Supply Chain Risk Management – Supply Chain Risk Management Plan
Control ID: SR-2
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.11
CISA Zero Trust Maturity Model 2.0 – Device Compliance and Health Verification
Control ID: Device Security - Advanced
NIS2 Directive – Supply Chain Security Measures
Control ID: Article 21.2(a)
DORA – ICT Third-Party Risk Management
Control ID: Article 28.1
ISO 27001:2022 – Information Security Policy for Supplier Relationships
Control ID: A.15.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Automotive
Supply-chain attacks on Android car head units create proxy botnets, compromising vehicle infotainment systems and enabling ad fraud through infected automotive hardware.
Consumer Electronics
Android-based head unit malware demonstrates supply-chain vulnerabilities in consumer electronics, turning legitimate devices into botnet nodes for monetization and fraud.
Transportation
Connected vehicle infrastructure faces supply-chain compromise risks, with malware targeting car systems for proxy operations while maintaining critical driving system integrity.
Computer Software/Engineering
Software supply-chain attacks targeting Android platforms require enhanced egress security, zero trust segmentation, and threat detection capabilities across development ecosystems.
Sources
- Hackers infect Android car head units with proxy botnet malwarehttps://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/Verified
- Android Head Unit Malware: Malicious Android Applications on Automotive Head Unitshttps://securelist.com/android-head-unit-malware/121106/Verified
- Google sues to disrupt BadBox botnet infecting 10 million deviceshttps://www.bleepingcomputer.com/news/security/google-sues-to-disrupt-badbox-20-botnet-infecting-10-million-devices/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained the MoYu group's supply-chain attack by limiting lateral movement across vehicle networks and restricting unauthorized outbound communications from compromised Android head units.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF would likely have constrained the malware's ability to establish persistent connections and communicate with external command infrastructure through application-aware traffic inspection.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have reduced the malware's system-level access scope by containing privileged operations within isolated workload boundaries and limiting cross-process communications.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have constrained the malware's ability to discover and access adjacent network devices by restricting lateral communications between vehicle network segments.
Control: Multicloud Visibility & Control
Mitigation: Visibility and control mechanisms would likely have detected and constrained the malware's persistent command channel communications through anomaly detection and traffic pattern analysis.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely have constrained unauthorized data transmission by blocking or limiting outbound communications from compromised head units to external attacker infrastructure.
Residual impact would likely be constrained to isolated head unit systems with reduced proxy effectiveness due to limited network reachability and restricted communication paths.
Impact at a Glance
Affected Business Functions
- Vehicle Infotainment Systems
- Navigation Services
- Connected Vehicle Features
- Automotive Software Distribution
Estimated downtime: N/A
Estimated loss: N/A
Vehicle information including device models, display resolution, Wi-Fi SSID, and MAC addresses. Potential privacy compromise through proxy network abuse and advertising fraud activities.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate automotive head units from critical vehicle control systems and limit lateral movement capabilities
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound communications from IoT devices to unknown C2 infrastructure
- • Enable Multicloud Visibility & Control to detect anomalous traffic patterns from embedded systems and identify botnet enrollment activities
- • Establish Encrypted Traffic (HPE) controls to secure MQTT and other IoT communications channels against man-in-the-middle attacks
- • Implement Threat Detection & Anomaly Response to baseline normal automotive system behavior and alert on suspicious proxy traffic or click-fraud activities



