Malware Hijacks Android Car Head Units to Build Proxy Botnet
Security researchers have uncovered a supply-chain attack targeting Android-based head units, the aftermarket infotainment screens installed in many vehicles. The malware rides in through a legitimate-looking device-update application, which once installed quietly enrolls the unit into a botnet.
Instead of stealing data directly, the attackers appear focused on monetization: infected units are used as proxy exit points, letting other actors route traffic through them, and are also leveraged for ad fraud by silently generating fake ad impressions or clicks in the background.
Because these head units run outdated, rarely patched Android builds and often ship from third-party manufacturers with loose security oversight, they're an attractive and largely invisible target compared to phones or PCs.