Executive Summary

In August 2026, Kaspersky researchers discovered a sophisticated supply-chain attack by the MoYu threat group targeting Android-based car head units manufactured by DoFun, a Chinese automotive software provider. The attackers compromised the legitimate TWCore system app to deliver JarService malware, which established command-and-control communication and downloaded additional payloads. The malware transformed infected head units into proxy botnet nodes and conducted advertising fraud operations, marking the first documented malware infection chain specifically designed for automotive head units. While the malware did not interfere with critical vehicle systems, it demonstrated a new attack vector in the expanding Internet of Things landscape.

This incident highlights the growing security risks in connected vehicle ecosystems as automotive manufacturers increasingly integrate internet-connected Android systems. The attack underscores vulnerabilities in automotive supply chains and the emergence of vehicles as new targets for cybercriminal monetization schemes.

Why This Matters Now

Connected vehicles represent a rapidly expanding attack surface as automotive manufacturers integrate more internet-enabled systems, creating new opportunities for cybercriminals to exploit automotive supply chains and establish persistent botnets in mobile environments.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attackers used a supply-chain attack method, compromising the legitimate TWCore system app from DoFun to deliver JarService malware that established command-and-control communication and downloaded additional malicious payloads.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained the MoYu group's supply-chain attack by limiting lateral movement across vehicle networks and restricting unauthorized outbound communications from compromised Android head units.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: CNSF would likely have constrained the malware's ability to establish persistent connections and communicate with external command infrastructure through application-aware traffic inspection.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely have reduced the malware's system-level access scope by containing privileged operations within isolated workload boundaries and limiting cross-process communications.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have constrained the malware's ability to discover and access adjacent network devices by restricting lateral communications between vehicle network segments.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Visibility and control mechanisms would likely have detected and constrained the malware's persistent command channel communications through anomaly detection and traffic pattern analysis.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely have constrained unauthorized data transmission by blocking or limiting outbound communications from compromised head units to external attacker infrastructure.

Impact (Mitigations)

Residual impact would likely be constrained to isolated head unit systems with reduced proxy effectiveness due to limited network reachability and restricted communication paths.

Impact at a Glance

Affected Business Functions

  • Vehicle Infotainment Systems
  • Navigation Services
  • Connected Vehicle Features
  • Automotive Software Distribution
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Vehicle information including device models, display resolution, Wi-Fi SSID, and MAC addresses. Potential privacy compromise through proxy network abuse and advertising fraud activities.

Recommended Actions

  • Implement Zero Trust Segmentation to isolate automotive head units from critical vehicle control systems and limit lateral movement capabilities
  • Deploy Egress Security & Policy Enforcement to block unauthorized outbound communications from IoT devices to unknown C2 infrastructure
  • Enable Multicloud Visibility & Control to detect anomalous traffic patterns from embedded systems and identify botnet enrollment activities
  • Establish Encrypted Traffic (HPE) controls to secure MQTT and other IoT communications channels against man-in-the-middle attacks
  • Implement Threat Detection & Anomaly Response to baseline normal automotive system behavior and alert on suspicious proxy traffic or click-fraud activities

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image