Malware infects Android-based automotive head unit firmware
66 points by campuscodi 2 hours ago | 19 comments

spicyjpeg 12 minutes ago
The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit. This seems to be a very similar situation to that of cheap generic Android TV streaming boxes, which often come pre-infected from the factory with residential proxies and other malware as well; most of the infrastructure is likely shared.
reply
Retr0id 54 minutes ago
> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet

People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.

reply
axegon_ 3 minutes ago
Almost, though I understand I am the exception rather than the rule: Personally I have an aftermarket android head unit since the standard one was incredibly basic, no real time navigation updates, updating maps was a pain in the ass and so on. Initially I did pair it with my phone but since it is an aftermarket unit from a company which apparently does not exist anymore, newer phones cannot be paired with it. So my only option was to go the opposite route and use my phone as a wireless hotspot(almost - there's a raspberry pi with openwrt between the two). And since I self-host everything, I had no choice but to hook it up to my vpn. That said, I understand the implications of doing this so ultimately the network access it gets is incredibly limited: everything that is not my music server and the maps provider has been cut off completely. The downside is that every now and then I get a "can't connect to google services" notification though that is technically reassuring from a security perspective.
reply
buckle8017 47 minutes ago
Head units can log location, navigation start and end points, call logs, call audio, and scrape full contact lists.

Just off the top of my head.

reply
Retr0id 45 minutes ago
That's scary from a user perspective, but harder to monetise at scale as an attacker. Proxy endpoints are just another commodity (and offer recurring revenue).
reply
wongarsu 7 minutes ago
If you infect tens of vehicles that's not that valuable. But if you infect ten thousand vehicles, convinced a trusted member of one of the bigger black hat forums it's real and have him vouch for your marketplace post, there should be some buyers for full movement profiles, call logs and address books of ten thousand people

And doing that doesn't really interfere with also setting up and selling proxy endpoints

reply
stymaar 36 minutes ago
Yeah, especially since most of these are already available for purchase from data brokers.
reply
kotaKat 31 minutes ago
It seems like this exploit is targeting those that keep their phones tethered for connectivity outwards or hooked a USB modem or a SIM card into a cell-equipped headunit.

The only valuable thing there is the relatively 'clean' mobile connection... and this malware's dropping a residential proxy endpoint on the headunit to take advantage of it. Bonus points if the headunit is always connected and always powered up to a +12v rail in the car, that's free and always-on real estate!

reply
brookst 23 minutes ago
Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition / accessory mode turns off, and go completely power-off 30-ish minutes later.

Otherwise any car sitting unused for a week or two would have a dead battery.

reply
dzdt 18 minutes ago
There are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. https://news.ycombinator.com/item?id=19751872
reply
jackdecker 45 minutes ago
For whatever reason, the idea of this being in my car is relatively scarier for me than if this was just my phone ?

I think partially as my mental model of both android auto and CarPlay is that they operate as a passthrough of my device rather than as an separate installation of the OS entirely (I wasn’t aware the head unit itself had the ability to install APKs independently).

Also, feel like John Gruber is going to have a field day with this one

reply
MBCook 27 minutes ago
Android Automotive is the infotainment system’s OS and runs fully without a phone.

Android Auto is the Google equivalent of CarPlay and runs on your phone.

It’s easy to confuse. Like watching Apple TV on your Apple TV in Apple’s TV app.

reply
dybber 31 minutes ago
I don’t believe this is Android auto running from a phone, but a situation where the manufacturer have used Android Automotive as operating system for the built in head unit. As e.g. on Volvo’s.
reply
inquirerGeneral 18 minutes ago
[dead]
reply
davoneus 52 minutes ago
The logical endpoint of the entire "the car as software" concept. Can't wait for the security vendors to start hawking "AV for your car"
reply
Retr0id 50 minutes ago
I hope we see "de-smartification" conversion kits that replace the electronics with more straightforward (and repairable) offline equivalents. The ultimate AV.
reply
MBCook 25 minutes ago
So to do this the attacker has to compromise the update servers at $CAR_COMPANY?
reply
bluGill 41 minutes ago
One more reason cars should not be internet connected. They last for decades and manufactures don't want to support their cars that long. Always proxy to a phone and the attack surface is limited to things that are updated.
reply
1970-01-01 33 minutes ago
..to add to a botnet for click fraud.

The duality of cybersecurity is interesting. Sometimes the high bar is cleared just to enable a low bar to go lower. Those PLCs monitoring water were ignored for a very long time because they couldn't click on ads. It took a war for them to become a target.

reply
IshKebab 17 minutes ago
Um so which car is this? tw.com doesn't seem to be in use.
reply
miohtama 40 minutes ago
[flagged]
reply
sehw 27 minutes ago
[dead]
reply
lvbyte 46 minutes ago
[dead]
reply