{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/twcore/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["MoYu Group"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TWCore"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["DoFun"],"content_html":"\u003cp\u003eKaspersky researchers identified a sophisticated campaign attributed to the MoYu Group, an actor previously linked to the BADBOX botnet, targeting Android-based automotive head units. The attack leverages the legitimate TWCore system application, responsible for analytics and OTA updates, to deliver malicious payloads. Attackers utilize an MQTT message broker hosted on the domain cardoor.cn to send instructions to the TWCore application, which then automatically downloads and installs arbitrary APKs on the head unit.\u003c/p\u003e\n\u003cp\u003eThe malware, identified as a multi-stage downloader (JarService), operates silently without a user interface. Its primary objectives include ad fraud and the recruitment of the compromised head units into a proxy botnet, taking advantage of the always-online nature and SIM capabilities of these automotive systems. This represents a significant shift in IoT targeting, moving from conventional devices to automotive entertainment systems. The vendor, DoFun, has been notified and has released fixes for the update distribution mechanism.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttackers maintain an MQTT broker on the attacker-controlled infrastructure (cardoor.cn).\u003c/li\u003e\n\u003cli\u003eThe compromised TWCore system app on the DoFun head unit connects to the MQTT broker for update instructions.\u003c/li\u003e\n\u003cli\u003eThe MQTT broker transmits a message containing a download URL and an installNotExists boolean flag to force installation.\u003c/li\u003e\n\u003cli\u003eTWCore downloads the malicious APK to its external cache directory at \u0026lt;TWCore external cache dir\u0026gt;/push/apk/.\u003c/li\u003e\n\u003cli\u003eThe JarService dropper is executed, which decrypts internal XOR-encrypted blocks to reveal secondary stage payloads.\u003c/li\u003e\n\u003cli\u003eThe secondary stage payload (a loader) initiates communication with the C2 server via an HTTP POST request, transmitting device and implant metadata.\u003c/li\u003e\n\u003cli\u003eThe loader uses reflection to execute the stage 3 payload, establishing proxy botnet functionality and ad fraud routines.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign results in the recruitment of automotive head units into a large-scale proxy botnet and facilitates unauthorized ad fraud. This compromises the integrity of the vehicle's embedded system, potentially leading to increased data usage costs for users and the abuse of vehicle connectivity for malicious traffic routing.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eMonitor network traffic for connections to cardoor.cn, which serves as the MQTT infrastructure for the malicious update instructions.\u003c/li\u003e\n\u003cli\u003eAudit Android head unit firmware and update channels to ensure software is only retrieved from legitimate, verified manufacturer endpoints.\u003c/li\u003e\n\u003cli\u003eDeploy detection logic for unauthorized package installation activity originating from the com.tw.core package name.\u003c/li\u003e\n\u003cli\u003eBlock communication to known malicious infrastructure used by the MoYu Group in the proxy botnet operations.\u003c/li\u003e\n\u003cli\u003eIf managing large fleets of Android-based automotive systems, restrict outbound MQTT connections to only known, authenticated manufacturer brokers.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-21T13:15:58Z","date_published":"2026-08-21T13:15:58Z","id":"https://feed.craftedsignal.io/briefs/2026-08-android-head-unit-malware/","summary":"The MoYu Group is distributing multi-stage Android malware through compromised firmware updates on DoFun head units to facilitate ad fraud and proxy botnet recruitment.","title":"MoYu Group Targets Android Automotive Head Units via Compromised Firmware Updates","url":"https://feed.craftedsignal.io/briefs/2026-08-android-head-unit-malware/"}],"language":"en","title":"CraftedSignal Threat Feed - TWCore","version":"https://jsonfeed.org/version/1.1"}