Live data from Hacker News

Malware infects Android-based automotive head unit firmware

securelist.com

81–90 of 154 posts

Re: Malware infects Android-based automotive head unit firmware

#81
post #2

> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.

Head units can log location, navigation start and end points, call logs, call audio, and scrape full contact lists. Just off the top of my head.

Some head units (working with a 1st party one atm) have two networks: OEM-paid (unlimited data) and user-paid. A 3rd party apk would be consuming all bought traffic quite soon.

Also typical Android permissions still apply. The user would need to grant the malicious app contacts, call logs, etc permissions.

Re: Malware infects Android-based automotive head unit firmware

#82
post #74
post #39

Earlier quoted context omitted.

They are always wired to battery power though. The point is that it could look powered off, and still be running a proxy.

You would hope that the ignition switch really cuts the power to the head unit when it is switched to off.

No you wouldn’t, because then you always have a cold boot of the headunit, even if you just accidentally hit the ignition. Users want the head unit to resume within a few seconds. Just like their phone.

Re: Malware infects Android-based automotive head unit firmware

#83
post #16

Earlier quoted context omitted.

Android Automotive is the infotainment system’s OS and runs fully without a phone. Android Auto is the Google equivalent of CarPlay and runs on your phone. It’s easy to confuse. Like watching Apple TV on your Apple TV in Apple’s TV app.

So I can use android auto on an android automotive head unit - got it but also this seems needlessly confusing naming structure. Apple TV comparison is apt lol

It makes perfect sense in isolation. It’s a good name.

Unfortunately Android Auto already existed. So it’s confusing.

Re: Malware infects Android-based automotive head unit firmware

#84
post #68
post #65

Earlier quoted context omitted.

> It cannot self-propagate to any Android-based head unit Article does not say that.

Headline really quite clearly implies it, though. I think the correction is apt. Bottom line is that lots of HN commenters here, as is our wont, will see this as a platform bug with a hated rival and not a bad third party integration that introduced vulnerabilities. Like, if it was a Linux-based edge system from some fly-by-night contractor, would you be OK with a headline like "Malware infects Debian based refrigera…

It’s no different than how the old Ford Sync or something else could have been compromised.

The two big things here in my mind are:

1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out

2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW/Volvo/whoever

Re: Malware infects Android-based automotive head unit firmware

#85
post #2

> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.

Some automakers like Nissan bring their own 4G SIM, which makes the pairing of phone not important, as the head unit can access Internet by itself

Re: Malware infects Android-based automotive head unit firmware

#86
post #2

> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.

"Pairing" with a head unit is not an open socket to dump anything you care to down the wire. That would require finding a rather remarkable vulnerability in one of the audio/address book/screen mirroring APIs the devices use.

Re: Malware infects Android-based automotive head unit firmware

#87

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

Why do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor's update server was compromised? If so why don't they just say so.

Re: Malware infects Android-based automotive head unit firmware

#88
post #2

> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.

"Pairing" with a head unit is not an open socket to dump anything you care to down the wire. That would require finding a rather remarkable vulnerability in one of the audio/address book/screen mirroring APIs the devices use.

Bluetooth RCEs have happened in the past and will happen again.

Re: Malware infects Android-based automotive head unit firmware

#89
post #41
post #28

Earlier quoted context omitted.

Indeed this is an odd disclosure and I am not familiar with past posts by them. Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.

https://en.wikipedia.org/wiki/Kaspersky_and_the_Russian_gove...

Oh, I see I'm getting downvoted by the Russian bots, quelle surprise.

Re: Malware infects Android-based automotive head unit firmware

#90
post #49

Earlier quoted context omitted.

> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?

Wireless CarPlay uses Bluetooth to exchange SSID and key info before switching over to WiFi for the duration of the session.

Wow that's cursed, never realized that's how it worked.
Post reply on HN