GKRootWire
Cloud & Sysadmin Microsoft Confirms Preview Update Wipes Out Desktop SettingsAI Nvidia to Acquire Hugging Face for $12.9 BillionDev Tools A Deep Dive Into Intrusive Linked ListsGadgets DJI's Romo 2 Robovac Adds Local-Only Mode After Privacy ScareAI Nvidia Reportedly Moves to Acquire Hugging FaceAI Anthropic Launches Claude Tools for AI Shopping AgentsCloud & Sysadmin Microsoft Confirms Preview Update Wipes Out Desktop SettingsAI Nvidia to Acquire Hugging Face for $12.9 BillionDev Tools A Deep Dive Into Intrusive Linked ListsGadgets DJI's Romo 2 Robovac Adds Local-Only Mode After Privacy ScareAI Nvidia Reportedly Moves to Acquire Hugging FaceAI Anthropic Launches Claude Tools for AI Shopping Agents
Security

Malware Hijacks Android Car Head Units to Build Proxy Botnet

A compromised device-update app is turning aftermarket car infotainment systems into unwitting nodes for a proxy network and ad-fraud scheme.

Security researchers have uncovered a supply-chain attack targeting Android-based head units, the aftermarket infotainment screens installed in many vehicles. The malware rides in through a legitimate-looking device-update application, which once installed quietly enrolls the unit into a botnet.

Instead of stealing data directly, the attackers appear focused on monetization: infected units are used as proxy exit points, letting other actors route traffic through them, and are also leveraged for ad fraud by silently generating fake ad impressions or clicks in the background.

Because these head units run outdated, rarely patched Android builds and often ship from third-party manufacturers with loose security oversight, they're an attractive and largely invisible target compared to phones or PCs.

Why it matters: Car infotainment systems are becoming a soft underbelly of IoT security: they're internet-connected, poorly maintained, and rarely monitored by owners or automakers. This case shows attackers don't need to hack the vehicle's core systems to profit — turning idle hardware into rented bandwidth is enough, and it's a model likely to spread to other neglected embedded devices.

Sources: BleepingComputer