• Sources: Securelist report, HN discussion
  • Summary: Kaspersky researcher Dmitry Kalinin published the report on 2026-08-21, from a threat found while monitoring Android malware in June 2026. TWCore, a legitimate system app on DoFun head units that collects analytics and updates software, takes MQTT messages from a broker on a cardoor[.]cn subdomain naming APKs to download and install, and an installNotExists flag lets it install apps that were never present on the device. The chain runs three stages: a JarService dropper with no user interface, a loader that reports to a command and control server and fetches the next payload, and a clicker and reverse proxy loader that polls /cpc/api/task every 90 minutes and reports display resolution, device model, connected Wi-Fi SSID, and MAC address. Kaspersky states the purpose is ad fraud and a proxy botnet, attributes the activity with high confidence to the MoYu Group linked to the BADBOX botnet, and states it notified the vendor, which reported fixing the distribution scheme. The affected head unit firmware versions are not yet known, because the report names no version range.
  • Why it matters: The delivery path is the vendor's own update channel rather than a user install, so a device that only ever ran factory software was still reachable.

send feedback on this story