8 ms·
The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket
by spicyjpeg 24d ago
The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit. This seems to be a very similar situation to that of cheap generic Android TV streaming boxes, which often come pre-infected from the factory with residential proxies and other malware as well; most of the infrastructure is likely shared.
- manbash 24d agoIndeed this is an odd disclosure and I am not familiar with past posts by them. Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.
- _joel 24d agohttps://en.wikipedia.org/wiki/Kaspersky_and_the_Russian_government https://en.wikipedia.org/wiki/Kaspersky_and_the_Russian_gove...
- p-e-w 24d ago[flagged]
- DaSHacka 24d agoWelcome to Wikipedia
- orbital-decay 24d agoWikipedia's source policy makes it nearly impossible to refer to anything that is not in the media, and any sensitive article has to use weasel words like this. Are you just noting the issue with the article, or actually doubting that Kaspersky Labs is a de-facto FSB branch since at least 2015?
- atmosx 24d agoFSB? Oh you mean Russian “Federal Security Service” ?
- somenameforme 24d agoUp until 2015 all was good with Kaspersky. But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government. Over the next years Kaspersky opened a bunch of 'transparency centers' offering full code audits and inspection, relocated their core infrastructure and customer data to Switzerland - subsequently falling under their data regulations, and so on. And if they were in any way affiliated with the Russian (or any) government, there seems no logical reason they'd publicly share their findings of the NSA malware, let alone the other transparency actions. Their data would be vastly more valuable if kept secret, because it'd open the door to greater exploitation of US cyber activities and being able to covertly secure desired systems. Instead their actions benefited everybody, but obviously embarrassed the NSA and as a result the US. [1] - https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064459/Equation_group_questions_and_answers.pdf https://media.kasperskycontenthub.com/wp-content/uploads/sit...
- orbital-decay 24d agoKL is a credible shop, they basically founded the modern anti-malware industry and pioneered most basic techniques in the 90's and early 2000's, together with some of their then-rivals like Dr. Web. There's a reason they were trusted, and there's a reason they tried to deny their takeover, they have a genuinely earned reputation. This doesn't mean they aren't a FSB branch, in the same way e.g. NSO Group is a Mossad branch, with one difference that KL sell themselves as defensive and NSO Group doesn't. It was confirmed by KL employees in their socials that the management has been largely taken over by actual FSB officers. Some have left the company out of protest because they felt it's getting raided (отжим in Russia is not like your usual corporate takeover...). It's impossible to link it now as most of these people are living abroad since 2022 or earlier and either removed all their stuff or their socials entirely, some have renounced their citizenship by this point. But as a general rule, assume every important business in Russia is taken over by the government since 2022, either directly or indirectly. In 2026, whitewashing Kaspersky Labs of all companies is weird. >But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government There was also a war happening, which you aren't saying. >Over the next years Kaspersky opened a bunch of 'transparency centers' offering full code audits and inspection, relocated their core infrastructure and customer data to Switzerland - subsequently falling under their data regulations The audits are to check the checkboxes, they mean very little. Plenty of former Russian companies that moved abroad are keeping ties with the developers at home, despite all audits, fronting campaigns, and otherwise pretending they aren't (not all though, others did actually migrate). >if they were in any way affiliated with the Russian (or any) government I mean, YK himself is KGB and there are no former ones, as they say. KL is one of the main government cybersec contractors, for starters. In a country where the government controls most of the economy they are producing critical industrial security systems like data diodes and secure gateways with their own OS, you can go to their site and look at all this yourself. Cybersec industry in general is heavily affiliated with their respective governments, I don't think it's a secret for anyone and denying this is just silly. Some of them are more than others. >there seems no logical reason they'd publicly share their findings of the NSA malware ... Their data would be vastly more valuable if kept secret, because it'd open the door to greater exploitation of US cyber activities and being able to covertly secure desired systems. What? This doesn't make any sense, sorry. Security agencies usually publish or leak actions of their adversaries. >Instead their actions benefited everybody Did their inaction benefited anyone? RuNet which has been great got basically destroyed and turned into a safe haven for half of world's cybercriminals on their proud watch, and they aren't writing anything on this. They serve as part of their "roof". Note I'm not saying they aren't doing good things, you're right, it's pretty good when the spooks keep each other and cybercriminals in check, see the article in OP, Apple's hardware backdoors (Operation Triangulation), and many other cases.
- jibal 24d agoThe article is about a controversy involving allegations. There is plenty of evidence presented that the controversy and the allegations exist. (And if you dig into the links, there is plenty of evidence that the allegations are not without basis.) > “sources said” Yes, that's how Wikipedia works. https://en.wikipedia.org/wiki/Wikipedia:Neutral_point_of_view https://en.wikipedia.org/wiki/Wikipedia:Neutral_point_of_vie...
- _joel 24d agoOh, I see I'm getting downvoted by the Russian bots, quelle surprise.
- mschuster91 24d ago> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?
- dhc02 24d agoThe way I understand it, the connection is negotiated via BT, but then wifi is used for the fat data pipe to run the display.
- m-s-y 24d agoWireless CarPlay uses Bluetooth to exchange SSID and key info before switching over to WiFi for the duration of the session.
- NewJazz 24d agoWow that's cursed, never realized that's how it worked.
- xp84 24d agoCursed is exactly how I would describe it - because it works great until it doesn’t and it of course gives you zero clue why it won’t connect.
- NLMichel 23d agoAnecdotally, I just got back from a holiday trip across Europe and crossed four international borders. At every single border crossing, my CarPlay session disconnected, and I had to toggle CarPlay off and back on in my phone settings to reconnect. Very strange, and I still have no idea what caused it.
- bluGill 24d agoIt's a good idea actually, but it's also really complex to get right. Early version of Android Auto could transfer over USB 2.0 instead of Bluetooth, which works, but it's not near as high bandwidth.
- reaperducer 24d agoIt cannot self-propagate to any Android-based head unit Remember that not that long ago viruses spread through floppy disks. Today, people share USB sticks full of music from one car to another all the time. They also bring their music from their home car to a rental car and back.
- charcircuit 24d agoMost people just bring their phone between cars for music.
- pdonis 24d agoMy phone is much clunkier to use for this than a USB stick. Plus my phone can't store my whole music library (because there's too much other stuff already on it), whereas a single USB stick does it easily with plenty of room to spare.
- charcircuit 24d agoPhones can access the whole internet. A USB stick can't stream Spotify or connect to the cloud.
- pdonis 23d agoWhich doesn't matter to me since the music I'm talking about is music I already have on the USB stick (because it's music I've collected over years and years of buying CDs, mostly before ways of streaming music over the Internet even existed), and I mostly want to listen to that. If I want something else, I can just use XM radio.
- dolmen 23d agoYou'll be surprised, but some places where a car can go have no phone connectivity.
- xp84 24d agoI’ve never met anyone irl who used USB sticks full of music. I know the capability is there in most cars, just never seen it. It seems like Bluetooth capability and Spotify/Apple Music landed in mainstream cars too soon after “play MP3s from USB” was added, for that to catch on.
- chrisjj 24d ago> It cannot self-propagate to any Android-based head unit Article does not say that.
- ajross 24d agoHeadline really quite clearly implies it, though. I think the correction is apt. Bottom line is that lots of HN commenters here, as is our wont, will see this as a platform bug with a hated rival and not a bad third party integration that introduced vulnerabilities. Like, if it was a Linux-based edge system from some fly-by-night contractor, would you be OK with a headline like "Malware infects Debian based refrigerators"? What'd Debian do?
- MBCook 24d agoIt’s no different than how the old Ford Sync or something else could have been compromised. The two big things here in my mind are: 1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out 2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW/Volvo/whoever
- ajross 24d agoThis is not Android Auto though, which is an entirely different product suite designed to connect a OEM infotainment system to an Android device owned by the vehicle operator. That protocol is proprietary, Google-owned and managed, not part of AOSP, and not available to the integrator of the software in question. The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software stack based on AOSP. It's not even "Android" in a product marketing sense. Again, it's like blaming Debian because some loon stuffed it in a wifi NAS or whatever and put a backdoor into their UI. It's insane.
- MBCook 24d agoDo you mean Android Automotive?
- markus_zhang 24d agoThis makes me think whether the whole chain is an intelligence side business — sell cheap electronics for profit and at the same time own them too.
- ghostly_s 24d agoWhy do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor's update server was compromised? If so why don't they just say so.
- supriyo-biswas 24d agoTo avoid charges of libel.
- wbl 24d agoIn America its not libel if it's true
- apublicfrog 24d agoI see nothing at a glance about the author (Dmitry Kalinin) being American, so I can't imagine that is relevant.
- bluGill 24d agothere is the problem. We don't know what country is in question. There are some countries where the truth is not a defense against libel. Thus, depending on where the author is from, or for that matter the publisher or other people who might happen to be in the chain, there could be a libel case if the truth was stated.
- camkego 24d agoInteresting how there is possibly a new category of residential proxy malware “automotive proxy malware”
- dolmen 23d agoThis is just another mobile device. It even has a SIM card.