GKRootWire
Gadgets Fairphone 6 Plus and Framework 12 Push the Case for Repairable TechSecurity Windows Named Pipes Are a Quiet Privilege-Escalation Risk, Security Firm WarnsGadgets Pixel 11 Pro XL Review: Faster Cameras, Familiar PhoneGadgets Amazon Raises Prices on Echo, Kindle, and Fire TV Devices by Up to 60 PercentSecurity Malware Hijacks Android Car Head Units to Build Proxy BotnetDev Tools Model Context Protocol Team Charts Next Phase With New RoadmapGadgets Fairphone 6 Plus and Framework 12 Push the Case for Repairable TechSecurity Windows Named Pipes Are a Quiet Privilege-Escalation Risk, Security Firm WarnsGadgets Pixel 11 Pro XL Review: Faster Cameras, Familiar PhoneGadgets Amazon Raises Prices on Echo, Kindle, and Fire TV Devices by Up to 60 PercentSecurity Malware Hijacks Android Car Head Units to Build Proxy BotnetDev Tools Model Context Protocol Team Charts Next Phase With New Roadmap
Security

Malware Hijacks Android Car Head Units to Build Proxy Botnet

A compromised device-update app is turning aftermarket car infotainment systems into unwitting nodes for a proxy network and ad-fraud scheme.

Security researchers have uncovered a supply-chain attack targeting Android-based head units, the aftermarket infotainment screens installed in many vehicles. The malware rides in through a legitimate-looking device-update application, which once installed quietly enrolls the unit into a botnet.

Instead of stealing data directly, the attackers appear focused on monetization: infected units are used as proxy exit points, letting other actors route traffic through them, and are also leveraged for ad fraud by silently generating fake ad impressions or clicks in the background.

Because these head units run outdated, rarely patched Android builds and often ship from third-party manufacturers with loose security oversight, they're an attractive and largely invisible target compared to phones or PCs.

Why it matters: Car infotainment systems are becoming a soft underbelly of IoT security: they're internet-connected, poorly maintained, and rarely monitored by owners or automakers. This case shows attackers don't need to hack the vehicle's core systems to profit — turning idle hardware into rented bandwidth is enough, and it's a model likely to spread to other neglected embedded devices.

Sources: BleepingComputer