Hackers infect Android car head units with proxy botnet malware
-
A supply-chain attack is targeting Android-based car head units by abusing a legitimate device-update application to distribute malware. The compromised devices are then pulled into a proxy botnet or exploited for ad fraud, turning the vehicle’s entertainment system into a tool for illicit financial gain.
The malicious campaign works by modifying the update mechanism of the head unit’s software, allowing the attacker to push a trojanized payload instead of a genuine firmware patch. Once installed, the malware establishes a persistent connection to a command-and-control server, awaiting instructions. Affected devices are then used as residential proxies to route malicious traffic, or are directed to load hidden ads in the background, which can degrade system performance and increase data usage for the owner.
Key technical details from the investigation include:
- The malicious package is delivered through the same app used for legitimate system updates, meaning users may not notice any difference during installation.
- The malware requests permissions typically reserved for system-level operations, allowing it to run with elevated privileges and remain hidden from standard security scans.
- Infected head units communicate with the attacker’s infrastructure over standard HTTPS, making traffic-based detection difficult for users or network administrators.
- At least one variant of the malware checks for an active internet connection before launching its payload, likely to avoid analysis in offline sandboxes.
For car owners, there is no immediate public tool to detect the infection, as the malware is signed with a valid developer certificate. Recommended mitigations include restricting head unit updates to official sources, monitoring for unusual network traffic from the vehicle, and disabling unknown sources in the Android settings if available. If a head unit is suspected of being compromised, a factory reset may remove the malware, but the underlying supply-chain risk remains until the vendor releases a patched update.
Source: BleepingComputer
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login