MoYu Group is a threat actor group attributed with high confidence to the BADBOX ad fraud and residential proxy scheme. They were previously exposed by HUMAN Satori and are now linked to the first documented malware targeting Android car head units, using built-in updaters to distribute malware for ad fraud and proxy botnet operations.