MoYu hijacks a legitimate DoFun app to turn Android head units into a proxy botnet
An infection chain targeting Android car head units delivers the JarService malware through DoFun’s own TWCore update app. Kaspersky attributes the operation to the MoYu group behind the BadBox botnet — the first documented malware chain built specifically for this class of device.