Malware infects Android-based automotive head unit firmware
21–30 of 154 posts
Re: Malware infects Android-based automotive head unit firmware
#22Re: Malware infects Android-based automotive head unit firmware
#23Re: Malware infects Android-based automotive head unit firmware
#24Earlier quoted context omitted.
Head units can log location, navigation start and end points, call logs, call audio, and scrape full contact lists. Just off the top of my head.
That's scary from a user perspective, but harder to monetise at scale as an attacker. Proxy endpoints are just another commodity (and offer recurring revenue).
And doing that doesn't really interfere with also setting up and selling proxy endpoints
Re: Malware infects Android-based automotive head unit firmware
#25> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.
Re: Malware infects Android-based automotive head unit firmware
#26Earlier quoted context omitted.
That's scary from a user perspective, but harder to monetise at scale as an attacker. Proxy endpoints are just another commodity (and offer recurring revenue).
Yeah, especially since most of these are already available for purchase from data brokers.
Re: Malware infects Android-based automotive head unit firmware
#27Re: Malware infects Android-based automotive head unit firmware
#28The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…
Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.
Re: Malware infects Android-based automotive head unit firmware
#29Earlier quoted context omitted.
It seems like this exploit is targeting those that keep their phones tethered for connectivity outwards or hooked a USB modem or a SIM card into a cell-equipped headunit. The only valuable thing there is the relatively 'clean' mobile connection... and this malware's dropping a residential proxy endpoint on the headunit to take advantage of it. Bonus points if the headunit is always connected and always powered up to…
Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition / accessory mode turns off, and go completely power-off 30-ish minutes later. Otherwise any car sitting unused for a week or two would have a dead battery.
Re: Malware infects Android-based automotive head unit firmware
#30For whatever reason, the idea of this being in my car is relatively scarier for me than if this was just my phone ? I think partially as my mental model of both android auto and CarPlay is that they operate as a passthrough of my device rather than as an separate installation of the OS entirely (I wasn’t aware the head unit itself had the ability to install APKs independently). Also, feel like John Gruber is going to…
Android Automotive is the infotainment system’s OS and runs fully without a phone. Android Auto is the Google equivalent of CarPlay and runs on your phone. It’s easy to confuse. Like watching Apple TV on your Apple TV in Apple’s TV app.