Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: proxy-botnet (1 article)Clear

First car head unit malware spreads through built-in Android updaters

Kaspersky documented what it calls the first malware found on a car head unit with an infection chain built specifically for that kind of device. The malware spreads through the built-in software updaters of certain Android-based automotive head unit firmware, then pulls a multi-stage downloader that runs ad fraud and enrolls the unit into a reverse-proxy botnet. Researchers attribute it with high confidence to a group tied to the BADBOX ad-fraud and residential-proxy operation. A head unit is the central console that handles media and, on many vehicles, some vehicle functions, so malware delivered through its own update mechanism is a notable expansion of automotive supply-chain risk.

Check
For fleets and connected-vehicle programs, ask head unit and firmware suppliers about the integrity of their built-in updaters, and monitor automotive and IoT devices for proxy or ad-fraud traffic.
Affected
Vehicles using affected Android automotive head unit firmware whose built-in updater delivered the malware; infected units run ad fraud and act as reverse-proxy nodes, and the head unit has partial vehicle-function access.
Fix
Treat the firmware update channel as a supply-chain trust boundary, source head units from vendors with signed verified updates, monitor connected vehicles for anomalous outbound traffic, and track this actor's proxy infrastructure.