
MoYu-linked malware hijacks Android car head units to form proxy botnet
Kaspersky attributes a MoYu group operation to a supply-chain-style attack that infected DoFun Android-based car head units with a rogue update app, dropping JarService to load a second-stage payload that communicates with a C2 server and accepts multiple commands. The malware turns the head unit into a proxy botnet node for ad fraud via a reverse-proxy module dubbed zhima, while still not interfering with vehicle control. DoFun said the issue was resolved after being alerted, and the researchers noted this as the first documented malware infection chain targeting car head units.
