Android Car Head Units Are Getting Hacked Through Their Built-In Updates
Researchers at Securelist discovered a new type of Android malware that infects car head units without any user interaction using the built-in updater.
The malware doesn't need to trick you to install it, it can install itself without you having to do anything.
Head units deal with the multimedia functions of a car as well as having control over some functions of the car itself. According to the researchers, this is the first documented case of malware specifically targeting automotive head units.
While most malware that's designed to run on Android can also run on Android head units, typically they aren't specifically targeted since most data that an attacker would want is on the users' phone. For example, a malicious banking app wouldn't work on a head unit since mobile banking is done on smartphones.
These head units can still be juicy targets though. Cars nowadays typically contain SIM cards that allow them to connect to the internet and receive updates, power their navigation, and use other online features.
The idea of hackers having control over your car is scary, even if it's not full control. However, the trojan here was trying to add cars to a malicious botnet, specifically the BADBOX botnet.
BADBOX has been found in cheap and insecure smart devices such as TVs and low-cost Android tablets. It generates fake ad revenue by launching hidden ads and clicking on them. It also routes traffic through your devices without your permission, which could very well be linked to criminal activity.
The manufacturer of the head units, DoFun, says they've fixed the security issues.
Security inside cars is almost non-existent and the attack surface is massive. Modern cars contain over 300 million lines of code from over 100 electronic control units from different manufacturers, all with their own dedicated chips and software and firmware stacks. It's predicted that they will reach 600 million lines of code by 2027.
Car manufacturers continue to race to add self-driving features, agentic AI, and now cameras pointed at the driver at all times. All of these represent massive attack surface that needs to be addressed, especially now that cars are actively being targeted by malware in a way we've never seen before.
There is a push for cars to have more security for their ECUs, such as implementing secure boot, adding post-quantum cryptography, and more authentication between ECUs.
Community Discussion