Kaspersky Identifies Graphless Malware in Android Car Radios Linked to BADBOX Network

Kaspersky's research published on August 22 reveals that the JarService malware, attributed to the MoYu Group, installs itself in DoFun's Android car radios via legitimate firmware and operates as an invisible botnet to the driver.
Kaspersky researchers published a detailed analysis on Friday, August 22, of a malware strain dubbed JarService, designed for Android car radios manufactured by the Chinese company Shenzhen Driving Control Technology, commercially known as DoFun. This discovery expands the BADBOX criminal network, previously associated mainly with fake smart TVs and set-top boxes, to the automotive electronics segment.
Dmitry Kalinin, a Kaspersky researcher who authored the report published on Securelist, explains that JarService operates without any graphical interface or visible icon to the user. The code is silently installed by TWCore, a legitimate firmware updater provided by DoFun itself. Upon startup, the service connects to the command and control server cardoor[.]cn using the MQTT protocol, typically associated with Internet of Things applications due to its low bandwidth consumption.
Kaspersky confidently attributes the operation to the MoYu Group. This group is responsible for the BADBOX infrastructure identified in previous campaigns, where millions of low-cost Android devices reached retail with compromised firmware already in the manufacturing supply chain. The overlapping IP addresses and domain structure between operations were the primary criteria for the researchers' attribution.
According to Kalinin, infected devices perform two functions for the operators: they act as residential proxy nodes, masking third-party traffic through the vehicle's broadband connection, and execute digital advertising fraud by displaying ads in the background without human interaction. Both are invisible to the driver and have minimal apparent performance impact on the system, making detection by average users difficult.
DoFun, a provider of car radios for markets such as Brazil, India, and Southeast Asia, confirmed to Kaspersky that a firmware patch was distributed after the researchers' private notification. However, the company did not issue a public statement, did not specify the number of affected units, nor the period during which the vulnerable devices were available on the market. The lack of transparency creates practical issues for distributors and resellers marketing the brand's products.
In Brazil, third-party Android car radios are widely installed in popular vehicles as a low-cost alternative to factory original systems. The market is growing alongside the popularity of vehicles equipped for Android Auto but lacks the security requirements that automakers impose on their approved suppliers. Kaspersky did not disclose the number of compromised units active globally.
The attack surface introduced by connected car radios is more complex than that of traditional smart TVs. A vehicle transmits real-time location data, connects to public and enterprise Wi-Fi networks, and may be linked to payment applications or streaming accounts. Kalinin notes that, so far, JarService has not exploited these additional capabilities, but the architecture allows for expansion modules to be delivered by the C2 server at any time.
The use of the MQTT protocol warrants specific attention from corporate security teams. Unlike conventional HTTPS traffic, persistent MQTT sessions are rarely inspected by corporate firewalls that filter traffic from fleets connected to internal networks. An infected car radio parked in a corporate garage could serve as a persistent entry point without triggering conventional intrusion detection alerts.
For CISOs managing fleets or allowing employees to connect aftermarket car radios to corporate networks via USB or Wi-Fi, Kaspersky recommends three measures: check firmware updates with the local distributor, isolate these devices on dedicated network segments, and monitor outgoing MQTT traffic on non-standard ports. Indicators of compromise, including hashes of JarService and the domain cardoor[.]cn, are available in the public report on Securelist.
The full extent of the BADBOX network as a criminal infrastructure remains uncertain. Companies such as Human Security and Trend Micro have already documented earlier variants in smart TVs and Android tablets. The car radio represents the first confirmed incursion into automotive hardware, indicating that the MoYu Group is systematically expanding its target device portfolio.