The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit. This seems to be a very similar situation to that of cheap generic Android TV streaming boxes, which often come pre-infected from the factory with residential proxies and other malware as well; most of the infrastructure is likely shared.
show comments
Retr0id
> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet
People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.
show comments
dzdt
There are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. https://news.ycombinator.com/item?id=19751872
show comments
jackdecker
For whatever reason, the idea of this being in my car is relatively scarier for me than if this was just my phone ?
I think partially as my mental model of both android auto and CarPlay is that they operate as a passthrough of my device rather than as an separate installation of the OS entirely (I wasn’t aware the head unit itself had the ability to install APKs independently).
Also, feel like John Gruber is going to have a field day with this one
show comments
davoneus
The logical endpoint of the entire "the car as software" concept. Can't wait for the security vendors to start hawking "AV for your car"
show comments
jiaosdjf
"How has the automotive industry adapted to decades of computing best practices?"
- Head units connected to CAN bus with bluetooth vulnerabilities allowing attacker to remotely activate locks and windows and sometimes even driving controls
- Unsecured CAN bus cables everywhere allowing cars to be stolen through headlights and behind mud guard flaps
- Keyless entry basically a shit show of faraday pouches
- OBD port allowing thieves to clone a full key in seconds
- Even cars in decent neighbourhoods have to use steering locks
Sorry but this is a fucking joke and the automotive industry is cancer.
At least Tesla actually bothers with user updates and production improvements, most other manufacturers just shit out the same model 5 years in a row with an extra cup holder and USB port (probably rootable) if you're lucky. That said, Tesla's insistence that everything be done by touch screen is dog shit.
All this and still for 99% of cars my iPhone stuck to the dashboard provides better maps and entertainment and yet they can't even make a fucking phone holder standard, not even a fucking mounting point so I don't have to block an air vent.
show comments
gchamonlive
Can't be safer than the non-entertainment system from WV Up! that's just a built-in head mount for your phone. Grab one with a large screen and it's the safest thing you can get. Android still has an auto mode for this where it controls the car's audio system through headless bindings, not sure this malware would target this, but just by being a simpler system chances are it's safer too
1970-01-01
..to add to a botnet for click fraud.
The duality of cybersecurity is interesting. Sometimes the high bar is cleared just to enable a low bar to go lower. Those PLCs monitoring water were ignored for a very long time because they couldn't click on ads. It took a war for them to become a target.
show comments
MBCook
So to do this the attacker has to compromise the update servers at $CAR_COMPANY?
show comments
hndbwksam7
Concise and useful, rare combo
bluGill
One more reason cars should not be internet connected. They last for decades and manufactures don't want to support their cars that long. Always proxy to a phone and the attack surface is limited to things that are updated.
doublerabbit
Norton AntiVirus for your car ECU's. Protect your carfor just $220.95/month *
* Cars without subscription causes acceleration to be restricted to 60mph.
After discovering the new OLED televisions come with antivirus, I'm done with thinking technology will ever be secure.
show comments
zb3
I'd not consider it malware if its sole purpose is to do ad/click fraud. The user is not the target here, the user's enemies are :)
IshKebab
Um so which car is this? tw.com doesn't seem to be in use.
waazy
this is crazy
tiahura
Apple's gatekeeping doesn't make IPhone users any safer.
The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit. This seems to be a very similar situation to that of cheap generic Android TV streaming boxes, which often come pre-infected from the factory with residential proxies and other malware as well; most of the infrastructure is likely shared.
> Since a head unit typically holds nothing of value to an attacker, one of the more likely attack scenarios using “classic” Android malware is infecting the device to recruit it into a botnet
People do pair them with their phones, though. I could imagine a future version of malware like this propagating laterally.
There are a lot of cars out there where the head unit has connection to the CAN bus. Which means this malware vector could be used to directly cause crashes. E.g. https://news.ycombinator.com/item?id=19751872
For whatever reason, the idea of this being in my car is relatively scarier for me than if this was just my phone ?
I think partially as my mental model of both android auto and CarPlay is that they operate as a passthrough of my device rather than as an separate installation of the OS entirely (I wasn’t aware the head unit itself had the ability to install APKs independently).
Also, feel like John Gruber is going to have a field day with this one
The logical endpoint of the entire "the car as software" concept. Can't wait for the security vendors to start hawking "AV for your car"
"How has the automotive industry adapted to decades of computing best practices?"
- Head units connected to CAN bus with bluetooth vulnerabilities allowing attacker to remotely activate locks and windows and sometimes even driving controls
- Unsecured CAN bus cables everywhere allowing cars to be stolen through headlights and behind mud guard flaps
- Keyless entry basically a shit show of faraday pouches
- OBD port allowing thieves to clone a full key in seconds
- Even cars in decent neighbourhoods have to use steering locks
Sorry but this is a fucking joke and the automotive industry is cancer.
At least Tesla actually bothers with user updates and production improvements, most other manufacturers just shit out the same model 5 years in a row with an extra cup holder and USB port (probably rootable) if you're lucky. That said, Tesla's insistence that everything be done by touch screen is dog shit.
All this and still for 99% of cars my iPhone stuck to the dashboard provides better maps and entertainment and yet they can't even make a fucking phone holder standard, not even a fucking mounting point so I don't have to block an air vent.
Can't be safer than the non-entertainment system from WV Up! that's just a built-in head mount for your phone. Grab one with a large screen and it's the safest thing you can get. Android still has an auto mode for this where it controls the car's audio system through headless bindings, not sure this malware would target this, but just by being a simpler system chances are it's safer too
..to add to a botnet for click fraud.
The duality of cybersecurity is interesting. Sometimes the high bar is cleared just to enable a low bar to go lower. Those PLCs monitoring water were ignored for a very long time because they couldn't click on ads. It took a war for them to become a target.
So to do this the attacker has to compromise the update servers at $CAR_COMPANY?
Concise and useful, rare combo
One more reason cars should not be internet connected. They last for decades and manufactures don't want to support their cars that long. Always proxy to a phone and the attack surface is limited to things that are updated.
I'd not consider it malware if its sole purpose is to do ad/click fraud. The user is not the target here, the user's enemies are :)
Um so which car is this? tw.com doesn't seem to be in use.
this is crazy
Apple's gatekeeping doesn't make IPhone users any safer.