Vendor
high
threat
MoYu Group Exploits Automotive Firmware Update Mechanism for Botnet Deployment
3 TTPs 2 IOCsThe MoYu Group is targeting DoFun Android-based vehicle head units by weaponizing the legitimate TWCore system update application to distribute JarService malware, turning automotive hardware into nodes for ad fraud and proxy botnets.
Android head unit firmware
MoYu Group
3t
2i
high
threat
MoYu Group Targets Android Automotive Head Units via Compromised Firmware Updates
2 TTPs 1 IOCThe MoYu Group is distributing multi-stage Android malware through compromised firmware updates on DoFun head units to facilitate ad fraud and proxy botnet recruitment.
TWCore
MoYu Group
2t
1i