MoYu Group, also referred to as MoYu, is a financially motivated cybercrime actor associated with the BADBOX botnet and BADBOX 2.0 residential-proxy ecosystem, including the IpMoYu proxy service. Its operations monetize compromised Android devices through advertising click fraud and residential-proxy services. Affected device categories include automotive infotainment head units, smart TVs, digital projectors, and other consumer IoT devices. MoYu's JarService campaign targets DoFun Android automotive head units by abusing the legitimate TWCore firmware-update application's ability to install additional applications. The multistage infection chain decrypts and loads successive payloads, communicates with command-and-control infrastructure, collects device information, and downloads executable modules. Its final-stage functionality supports automated advertisement interactions, attacker-controlled JavaScript execution in WebViews, arbitrary code execution, and reverse-proxy operation. The affected infotainment modules do not control critical driving systems. MoYu also distributes residential-proxy functionality through grey-market Android TV IPTV applications. These applications retrieve staged configuration and dynamically load the zhima module rather than embedding the proxy payload directly. Zhima converts infected devices into SOCKS5 and HTTP CONNECT proxy exit nodes through outbound connections to operator-controlled relays, avoiding externally exposed listening ports. The malware uses encrypted or obfuscated payloads and configuration, runtime module loading, and replaceable proxy-module builds. MoYu's activity has also been linked to the PXYEDGE and ProxyForU residential-proxy services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
41 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MoYu is a cybercrime group associated with Android botnets used for advertising click fraud and reverse-proxy operations. Its latest campaign targets DoFun automotive infotainment head units, abusing the TWCore firmware updater to install the multistage JarService downloader. Subsequent payloads include a click-fraud Trojan and a reverse-proxy module. Kaspersky attributes the campaign to MoYu with high confidence based on technical overlaps with its previous ad-fraud infrastructure. The reported infections do not pose physical risks to vehicle occupants.
Cybercriminal activity attributed with high confidence to MoYu involving a newly documented Android malware campaign targeting DoFun in-vehicle head units through the legitimate TWCore firmware update application, enabling ad fraud, residential proxy botnet creation, arbitrary code download/execution, and information exfiltration.
Conducting a supply-chain attack targeting Android-based car head units by abusing a legitimate DoFun device-update app to deliver malware used for ad fraud and to enlist compromised devices into a proxy botnet.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.