#MoYuGroup
August 24, 2026 at 8:34 AM
New Android malware is abusing the TWCore updater on automotive head units, ending in ad fraud and a proxy botnet via zhima. Kaspersky links the campaign to MoYu Group with high confidence. #TWCore #BADBOX #China
The invisible passenger in your car
Researchers uncovered a new Android malware campaign targeting Android-based automotive head unit firmware through the legitimate TWCore updater, making this the first documented infection chain of its kind on a car head unit. The multi-stage payload ends in a clicker and the zhima reverse proxy module, and Kaspersky attributes the activity with high confidence to the MoYu Group, an actor linked to BADBOX. #TWCore #JarService #zhima #MoYuGroup #BADBOX #DoFun
www.hendryadrian.com
August 21, 2026 at 10:15 AM