Android car head-unit firmware hijacked by MoYu/BADBOX-linked proxy botnet malware
Kaspersky's Securelist writeup attributes this to the MoYu Group — the actor behind the BADBOX botnet — abusing a legitimate DoFun firmware system app (TWCore) as the dropper for a JarService loader that pulls a module called zhima and enrolls the head unit in a residential-proxy botnet used for ad fraud and traffic laundering. It's the same TTP shape as BADBOX and BADBOX 2.0: a trusted OTA/update channel repurposed as the malware delivery path, this time on automotive infotainment hardware that ships with its own SIM for connectivity. If you're evaluating aftermarket or OEM Android head units, treat unexplained outbound proxy-style traffic or unexpected TWCore network activity as an IOC and pull the current BADBOX indicator set.