Hackers infect Android car head units with proxy botnet malware

Vira Manti

Published Aug 22, 2026, 5:57 PM UTC

Source: SecuritySource
- Supply-chain gremlins slipped proxy-botnet malware into Android car head units through a legit device-update app — because nothing screams "trusted update channel" like an unsealed cargo container full of ad-fraud bots. Who gets hurt: drivers whose infotainment systems quietly moonlight as relay nodes, and any fleet operator who assumed "Android Auto" meant "Android Secured." The botnet angle means your dashboard could be proxying someone else's traffic while you're still buffering podcasts. Check the seals on your update sources, audit any head unit pulling auto-updates from sketchy OEM portals, and stop kidding yourself that a carputer is less attackable than your phone. We're threadbare on zero-day details, so treat every update notification like it wants your chassis. Delivery signature applied.