Hackers infect Android car head units with proxy botnet malware
BLUF
A supply-chain compromise of Android car head units is turning vehicles into proxy bots and ad fraud tools via a trusted update mechanism.
NEWS
Threat actors are exploiting a legitimate device-update application within Android-based automotive head units to deploy malware. Once infected, these systems are recruited into a botnet used for proxy services or ad fraud campaigns. This attack leverages supply-chain trust to bypass security measures on connected vehicles.
Why I Care
Vehicle owners face privacy risks and potential performance degradation, while automakers risk brand damage and liability. The broader internet suffers from increased botnet traffic used to mask cyberattacks or inflate advertising metrics.
Next Steps
Automakers should audit update channels immediately and push security patches to affected head units. Drivers should monitor for unusual data usage or performance issues and report anomalies to manufacturers. Security teams should block known malicious domains associated with the botnet infrastructure.
Source: BleepingComputer ·