Live data from Hacker News

Malware infects Android-based automotive head unit firmware

securelist.com

121–130 of 154 posts

Re: Malware infects Android-based automotive head unit firmware

#121
post #85

Earlier quoted context omitted.

Some automakers like Nissan bring their own 4G SIM, which makes the pairing of phone not important, as the head unit can access Internet by itself

How long until the 4G networks are turned off? There are a lot of cars that have a 3G sim or even a 2G sim. They can do nothing because those networks have been turned off. At least I'm not aware of any car where they updated the radio in the car when the network got turned off. By contrast, I work for John Deere and just down the hall from me are people who made a ton of money when the 2G network got turned off beca…

> How long until the 4G networks are turned off? There are a lot of cars that have a 3G sim or even a 2G sim. They can do nothing because those networks have been turned off.

There's a good chance it will last longer than 3G. 5G was designed to coexist with 4G so a 5G base station can (optionally) use a 4G compatible beacon and use 4G for some timeslots and 5G for others. Even if 6G doesn't do the same, 4G can live until 5G is turned off. 2G and 3G needed a whole channel allocated, which was too much in the US anyway. I understand in some countries they turned off 3G but left one channel of 2G for industrial/embedded devices; maybe one channel per network or maybe one channel that all networks could roam to ... roaming seems more permissive outside the US, too.

Re: Malware infects Android-based automotive head unit firmware

#122

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

Why do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor's update server was compromised? If so why don't they just say so.

Cheap Android phones and tables often have built-in advertisement from manufacturer. One example of such software, it creates a window with Google Ads on top of browser window. The window is shown only when the browser is active to make it look like the ads is a part of the site. The ads appears only couple weeks after activation so that the user thinks it is a result of installation of some app and Youtube reviewers do not notice existence of malware. The adware consults a remote config which defines in what countries it should work. Another adware component automatically downloads and re-installs it if it is deleted.

I found all these details through examining the official firmware image and reverse engineering.

I don't remember if I reported Google Ads id to Google. It is interesting that Google doesn't notice and care about such use of their products.

Re: Malware infects Android-based automotive head unit firmware

#123
post #74
post #39

Earlier quoted context omitted.

They are always wired to battery power though. The point is that it could look powered off, and still be running a proxy.

You would hope that the ignition switch really cuts the power to the head unit when it is switched to off.

Lots of head units will lose presets when they lose power.

Re: Malware infects Android-based automotive head unit firmware

#124
post #95
post #85

Earlier quoted context omitted.

Some automakers like Nissan bring their own 4G SIM, which makes the pairing of phone not important, as the head unit can access Internet by itself

Keep in mind however that the 4G SIM is not there for the driver's benefit, but for Nissan's. It collects extremely invasive telemetry that is then sold to data brokers and consumed by car insurers and government agencies, among others. This is why I won't drive a car that I own without first removing the onboard modem.

Exactly and with the malware is much worse

Re: Malware infects Android-based automotive head unit firmware

#125
post #19

Earlier quoted context omitted.

Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition / accessory mode turns off, and go completely power-off 30-ish minutes later. Otherwise any car sitting unused for a week or two would have a dead battery.

I'm pretty certain my car could go months running Android in low power mode just from the 12v battery, never mind the traction battery. But no, they had to have the head unit boot on every start and everything is slow for a minute, especially since the last update. These people can't code for shit.

> I'm pretty certain my car could go months running Android in low power mode just from the 12v battery, never mind the traction battery.

Most traction batteries are behind a relay or something and won't be available for full time use...

Re: Malware infects Android-based automotive head unit firmware

#127

The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit.…

Interesting how there is possibly a new category of residential proxy malware “automotive proxy malware”

Re: Malware infects Android-based automotive head unit firmware

#128
post #4

Earlier quoted context omitted.

I hope we see "de-smartification" conversion kits that replace the electronics with more straightforward (and repairable) offline equivalents. The ultimate AV.

Don't see this happens any time soon. Many feedback loops in modern car is software based and interconnected with each other. Kits that works half as good without software would be very expensive to make.

I didn't say without any software at all.

Re: Malware infects Android-based automotive head unit firmware

#129

Earlier quoted context omitted.

Wikipedia's source policy makes it nearly impossible to refer to anything that is not in the media, and any sensitive article has to use weasel words like this. Are you just noting the issue with the article, or actually doubting that Kaspersky Labs is a de-facto FSB branch since at least 2015?

Up until 2015 all was good with Kaspersky. But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government. Over the next years Kaspersky opened a bunch of 'transparency centers' offering full code audits and inspection,…

KL is a credible shop, they basically founded the modern anti-malware industry and pioneered most basic techniques in the 90's and early 2000's, together with some of their then-rivals like Dr. Web. There's a reason they were trusted, and there's a reason they tried to deny their takeover, they have a genuinely earned reputation.

This doesn't mean they aren't a FSB branch, in the same way e.g. NSO Group is a Mossad branch, with one difference that KL sell themselves as defensive and NSO Group doesn't. It was confirmed by KL employees in their socials that the management has been largely taken over by actual FSB officers. Some have left the company out of protest because they felt it's getting raided (отжим in Russia is not like your usual corporate takeover...). It's impossible to link it now as most of these people are living abroad since 2022 or earlier and either removed all their stuff or their socials entirely, some have renounced their citizenship by this point. But as a general rule, assume every important business in Russia is taken over by the government since 2022, either directly or indirectly. In 2026, whitewashing Kaspersky Labs of all companies is weird.

>But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government

There was also a war happening, which you aren't saying.

>Over the next years Kaspersky opened a bunch of 'transparency centers' offering full code audits and inspection, relocated their core infrastructure and customer data to Switzerland - subsequently falling under their data regulations

The audits are to check the checkboxes, they mean very little. Plenty of former Russian companies that moved abroad are keeping ties with the developers at home, despite all audits, fronting campaigns, and otherwise pretending they aren't (not all though, others did actually migrate).

>if they were in any way affiliated with the Russian (or any) government

I mean, YK himself is KGB and there are no former ones, as they say. KL is one of the main government cybersec contractors, for starters. In a country where the government controls most of the economy they are producing critical industrial security systems like data diodes and secure gateways with their own OS, you can go to their site and look at all this yourself.

Cybersec industry in general is heavily affiliated with their respective governments, I don't think it's a secret for anyone and denying this is just silly. Some of them are more than others.

>there seems no logical reason they'd publicly share their findings of the NSA malware ... Their data would be vastly more valuable if kept secret, because it'd open the door to greater exploitation of US cyber activities and being able to covertly secure desired systems.

What? This doesn't make any sense, sorry. Security agencies usually publish or leak actions of their adversaries.

>Instead their actions benefited everybody

Did their inaction benefited anyone? RuNet which has been great got basically destroyed and turned into a safe haven for half of world's cybercriminals on their proud watch, and they aren't writing anything on this. They serve as part of their "roof".

Note I'm not saying they aren't doing good things, you're right, it's pretty good when the spooks keep each other and cybercriminals in check, see the article in OP, Apple's hardware backdoors (Operation Triangulation), and many other cases.

Post reply on HN