8 ms·
Malware infects Android-based automotive head unit firmware
- davoneus 25d agoThe logical endpoint of the entire "the car as software" concept. Can't wait for the security vendors to start hawking "AV for your car"
- Retr0id 25d agoI hope we see "de-smartification" conversion kits that replace the electronics with more straightforward (and repairable) offline equivalents. The ultimate AV.
- doublerabbit 25d agoIt's already in televisions. Not long now.
- Retr0id 25d ago> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.
- buckle8017 25d agoHead units can log location, navigation start and end points, call logs, call audio, and scrape full contact lists. Just off the top of my head.
- Retr0id 25d agoThat's scary from a user perspective, but harder to monetise at scale as an attacker. Proxy endpoints are just another commodity (and offer recurring revenue).
- stymaar 25d agoYeah, especially since most of these are already available for purchase from data brokers.
- Zigurd 25d agoThey're called data brokers because they have a buy side, too. That might be peanuts to you, but to an AliExpress seller, it could be most of their profit.
- wongarsu 25d agoIf you infect tens of vehicles that's not that valuable. But if you infect ten thousand vehicles, convinced a trusted member of one of the bigger black hat forums it's real and have him vouch for your marketplace post, there should be some buyers for full movement profiles, call logs and address books of ten thousand people And doing that doesn't really interfere with also setting up and selling proxy endpoints
- carstenhag 25d agoSome head units (working with a 1st party one atm) have two networks: OEM-paid (unlimited data) and user-paid. A 3rd party apk would be consuming all bought traffic quite soon. Also typical Android permissions still apply. The user would need to grant the malicious app contacts, call logs, etc permissions.
- lvbyte 25d ago[dead]
- jackdecker 25d agoFor whatever reason, the idea of this being in my car is relatively scarier for me than if this was just my phone ? I think partially as my mental model of both android auto and CarPlay is that they operate as a passthrough of my device rather than as an separate installation of the OS entirely (I wasn’t aware the head unit itself had the ability to install APKs independently). Also, feel like John Gruber is going to have a field day with this one
- dybber 25d agoI don’t believe this is Android auto running from a phone, but a situation where the manufacturer have used Android Automotive as operating system for the built in head unit. As e.g. on Volvo’s.
- MBCook 25d agoAndroid Automotive is the infotainment system’s OS and runs fully without a phone. Android Auto is the Google equivalent of CarPlay and runs on your phone. It’s easy to confuse. Like watching Apple TV on your Apple TV in Apple’s TV app.
- Zigurd 25d agoDid they hire their branding person from Microsoft? And how about AppFunctions (Google) and AppIntents (Apple)?
- 25d ago
- bluGill 25d agoOne more reason cars should not be internet connected. They last for decades and manufactures don't want to support their cars that long. Always proxy to a phone and the attack surface is limited to things that are updated.
- miohtama 25d ago[flagged]
- 1970-01-01 25d ago..to add to a botnet for click fraud. The duality of cybersecurity is interesting. Sometimes the high bar is cleared just to enable a low bar to go lower. Those PLCs monitoring water were ignored for a very long time because they couldn't click on ads. It took a war for them to become a target.
- deleted 25d ago[deleted]
- chrisjj 25d ago> Those PLCs monitoring water were ignored for a very long time because they couldn't click on ads. Somehow I doubt it. They're ripe for ransomware attack.
- sehw 25d ago[dead]
- MBCook 25d agoSo to do this the attacker has to compromise the update servers at $CAR_COMPANY?
- timmmmmmay 25d agono, the update servers at $sketchy_aliexpress_aftermarket_head_unit_company, probably somewhat easier
- IshKebab 25d agoUm so which car is this? tw.com doesn't seem to be in use.
- deleted 25d ago[deleted]
- dzdt 25d agoThere are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. https://news.ycombinator.com/item?id=19751872 https://news.ycombinator.com/item?id=19751872
- 01100011 25d agoAn aftermarket head unit connects to the CAN bus? The aftermarket head unit I installed certainly doesn't. Are you sure what you are saying, which is true for OEM units, applies to aftermarket ones?
- karlshea 25d agoMine does. Its dashboard shows fuel level and a bunch of other things and I can bring up a speedometer/rpm app. I believe the connection exists because the steering wheel buttons/iDrive talk to the original head unit over CAN.
- rootusrootus 25d agoThat’s wild, I’ve never run across a head unit that had me connect OBD2. I think I would just ignore that bit of the install instructions.
- karlshea 24d agoI did not connect ODB2. The HU I got puts itself as a passthrough to the stock BMW HU (which you still need to be able to use, you switch the screen to its output by holding down a button), and that connector includes CAN. There are numerous reasons the HU needs CAN, for example to get the steering wheel angle to be able to draw the guides over the backup camera feed. Or to switch to the backup camera feed when you put the car in reverse.
- rootusrootus 24d agoIt is really exposing the CAN bus, it is not some adjacent subsystem overlaying the steering guides and rearview video by interrupting the video signal? It's actually entirely coming from the aftermarket HU? That's fascinating! I wouldn't expect an aftermarket system to be too good at that functionality, guides tend to be carefully tuned for specific car/steering/camera combos. Ideally most cars should be relying heavily on data diodes to minimize the risk of a bad actor wreaking havoc. I know for sure some cars (there was a Jeep example as I recall) don't do that, but I kinda wonder which ones do. It seems like a pretty obvious attack vector worth protecting.
- spicyjpeg 25d agoThe article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit. This seems to be a very similar situation to that of cheap generic Android TV streaming boxes, which often come pre-infected from the factory with residential proxies and other malware as well; most of the infrastructure is likely shared.
- manbash 25d agoIndeed this is an odd disclosure and I am not familiar with past posts by them. Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.
- _joel 25d agohttps://en.wikipedia.org/wiki/Kaspersky_and_the_Russian_government https://en.wikipedia.org/wiki/Kaspersky_and_the_Russian_gove...
- p-e-w 25d ago[flagged]
- DaSHacka 25d agoWelcome to Wikipedia
- orbital-decay 25d agoWikipedia's source policy makes it nearly impossible to refer to anything that is not in the media, and any sensitive article has to use weasel words like this. Are you just noting the issue with the article, or actually doubting that Kaspersky Labs is a de-facto FSB branch since at least 2015?
- promptspheree 25d ago[flagged]
- gchamonlive 25d agoCan't be safer than the non-entertainment system from WV Up! that's just a built-in head mount for your phone. Grab one with a large screen and it's the safest thing you can get. Android still has an auto mode for this where it controls the car's audio system through headless bindings, not sure this malware would target this, but just by being a simpler system chances are it's safer too
- zb3 25d agoI'd not consider it malware if its sole purpose is to do ad/click fraud. The user is not the target here, the user's enemies are :)
- jiaosdjf 25d ago"How has the automotive industry adapted to decades of computing best practices?" - Head units connected to CAN bus with bluetooth vulnerabilities allowing attacker to remotely activate locks and windows and sometimes even driving controls - Unsecured CAN bus cables everywhere allowing cars to be stolen through headlights and behind mud guard flaps - Keyless entry basically a shit show of faraday pouches - OBD port allowing thieves to clone a full key in seconds - Even cars in decent neighbourhoods have to use steering locks Sorry but this is a fucking joke and the automotive industry is cancer. At least Tesla actually bothers with user updates and production improvements, most other manufacturers just shit out the same model 5 years in a row with an extra cup holder and USB port (probably rootable) if you're lucky. That said, Tesla's insistence that everything be done by touch screen is dog shit. All this and still for 99% of cars my iPhone stuck to the dashboard provides better maps and entertainment and yet they can't even make a fucking phone holder standard, not even a fucking mounting point so I don't have to block an air vent.
- smilespray 25d agoYou had me until you started giving Tesla the thumbs-up, despite your caveat.
- Telaneo 25d ago> "How has the automotive industry adapted to decades of computing best practices?" Simple. It hasn't.
- newtwentysix 23d agoI don't know tesla cars. I absolutely agree with the rest of your points
- doublerabbit 25d agoNorton AntiVirus for your car ECU's. Protect your carfor just $220.95/month * * Cars without subscription causes acceleration to be restricted to 60mph. After discovering the new OLED televisions come with antivirus, I'm done with thinking technology will ever be secure.
- Telaneo 25d agoEven from this perspective, it's pretty easy to make things more secure by having less technology. Have the infotainment system just be a blank canvas for Carplay or AA to display on (there does need to be a bit back and fourth, phone needs to send audio to car, car needs to send GPS, speed and state of charge to phone (not strictly necessary, but there are user benefits from the phone having this information). The car itself doesn't need a whole internet-connected general purpose computer attached to it, but doing that is an easy way for the manufacturer to supposedly add value. Similarly, the LG kerfuffle could be solved by their monitors just being monitors, and not throwing in pointless extras that just broadens their attack surface. Monitors don't need to be general purpose computing devices either. I shouldn't have to worry about general computing problems, like getting infected with malware, outside of computers that obviously are general purpose (i.e. phone, desktop, laptop, and anything else I intentionally set up with foreknowledge of it being general purpose and internet-connected, like a Raspberry Pi).
- tiahura 25d agoApple's gatekeeping doesn't make IPhone users any safer.
- hndbwksam7 25d agoConcise and useful, rare combo
- waazy 25d agothis is crazy
- codedokode 24d agoCould these proxies be sold to AI companies for scraping websites?
- coachdaniel2026 24d ago[flagged]