8/23/2026 at 2:11:27 PM
The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit. This seems to be a very similar situation to that of cheap generic Android TV streaming boxes, which often come pre-infected from the factory with residential proxies and other malware as well; most of the infrastructure is likely shared.by spicyjpeg
8/23/2026 at 6:53:46 PM
Why do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor's update server was compromised? If so why don't they just say so.by ghostly_s
8/24/2026 at 4:44:14 AM
Cheap Android phones and tables often have built-in advertisement from manufacturer. One example of such software, it creates a window with Google Ads on top of browser window. The window is shown only when the browser is active to make it look like the ads is a part of the site. The ads appears only couple weeks after activation so that the user thinks it is a result of installation of some app and Youtube reviewers do not notice existence of malware. The adware consults a remote config which defines in what countries it should work. Another adware component automatically downloads and re-installs it if it is deleted.I found all these details through examining the official firmware image and reverse engineering.
I don't remember if I reported Google Ads id to Google. It is interesting that Google doesn't notice and care about such use of their products.
by codedokode
8/24/2026 at 3:40:03 AM
> we would have to assume the vendor's update server was compromisedYou say "compromised". I say "monetised".
:sigh:
by bigiain
8/23/2026 at 7:53:45 PM
To avoid charges of libel.by supriyo-biswas
8/23/2026 at 8:51:24 PM
In America its not libel if it's trueby wbl
8/23/2026 at 9:21:14 PM
I see nothing at a glance about the author (Dmitry Kalinin) being American, so I can't imagine that is relevant.by apublicfrog
8/23/2026 at 11:41:24 PM
there is the problem. We don't know what country is in question. There are some countries where the truth is not a defense against libel. Thus, depending on where the author is from, or for that matter the publisher or other people who might happen to be in the chain, there could be a libel case if the truth was stated.by bluGill
8/24/2026 at 8:41:36 AM
> There are some countries where the truth is not a defense against libelGermany, for example. Utterly bizarre and baffling that a democracy protects its politicians this way. /s
by scoot
8/24/2026 at 4:02:47 PM
It's important for people to be able to critize elected officials.by wbl
8/23/2026 at 2:25:46 PM
Indeed this is an odd disclosure and I am not familiar with past posts by them.Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.
by manbash
8/23/2026 at 2:57:20 PM
https://en.wikipedia.org/wiki/Kaspersky_and_the_Russian_gove...by _joel
8/23/2026 at 7:03:36 PM
Oh, I see I'm getting downvoted by the Russian bots, quelle surprise.by _joel
8/23/2026 at 3:10:02 PM
[flagged]by p-e-w
8/23/2026 at 3:46:24 PM
Wikipedia's source policy makes it nearly impossible to refer to anything that is not in the media, and any sensitive article has to use weasel words like this. Are you just noting the issue with the article, or actually doubting that Kaspersky Labs is a de-facto FSB branch since at least 2015?by orbital-decay
8/24/2026 at 4:13:39 AM
Up until 2015 all was good with Kaspersky. But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government. Over the next years Kaspersky opened a bunch of 'transparency centers' offering full code audits and inspection, relocated their core infrastructure and customer data to Switzerland - subsequently falling under their data regulations, and so on.And if they were in any way affiliated with the Russian (or any) government, there seems no logical reason they'd publicly share their findings of the NSA malware, let alone the other transparency actions. Their data would be vastly more valuable if kept secret, because it'd open the door to greater exploitation of US cyber activities and being able to covertly secure desired systems. Instead their actions benefited everybody, but obviously embarrassed the NSA and as a result the US.
[1] - https://media.kasperskycontenthub.com/wp-content/uploads/sit...
by somenameforme
8/24/2026 at 6:53:22 AM
KL is a credible shop, they basically founded the modern anti-malware industry and pioneered most basic techniques in the 90's and early 2000's, together with some of their then-rivals like Dr. Web. There's a reason they were trusted, and there's a reason they tried to deny their takeover, they have a genuinely earned reputation.This doesn't mean they aren't a FSB branch, in the same way e.g. NSO Group is a Mossad branch, with one difference that KL sell themselves as defensive and NSO Group doesn't. It was confirmed by KL employees in their socials that the management has been largely taken over by actual FSB officers. Some have left the company out of protest because they felt it's getting raided (отжим in Russia is not like your usual corporate takeover...). It's impossible to link it now as most of these people are living abroad since 2022 or earlier and either removed all their stuff or their socials entirely, some have renounced their citizenship by this point. But as a general rule, assume every important business in Russia is taken over by the government since 2022, either directly or indirectly. In 2026, whitewashing Kaspersky Labs of all companies is weird.
>But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government
There was also a war happening, which you aren't saying.
>Over the next years Kaspersky opened a bunch of 'transparency centers' offering full code audits and inspection, relocated their core infrastructure and customer data to Switzerland - subsequently falling under their data regulations
The audits are to check the checkboxes, they mean very little. Plenty of former Russian companies that moved abroad are keeping ties with the developers at home, despite all audits, fronting campaigns, and otherwise pretending they aren't (not all though, others did actually migrate).
>if they were in any way affiliated with the Russian (or any) government
I mean, YK himself is KGB and there are no former ones, as they say. KL is one of the main government cybersec contractors, for starters. In a country where the government controls most of the economy they are producing critical industrial security systems like data diodes and secure gateways with their own OS, you can go to their site and look at all this yourself.
Cybersec industry in general is heavily affiliated with their respective governments, I don't think it's a secret for anyone and denying this is just silly. Some of them are more than others.
>there seems no logical reason they'd publicly share their findings of the NSA malware ... Their data would be vastly more valuable if kept secret, because it'd open the door to greater exploitation of US cyber activities and being able to covertly secure desired systems.
What? This doesn't make any sense, sorry. Security agencies usually publish or leak actions of their adversaries.
>Instead their actions benefited everybody
Did their inaction benefited anyone? RuNet which has been great got basically destroyed and turned into a safe haven for half of world's cybercriminals on their proud watch, and they aren't writing anything on this. They serve as part of their "roof".
Note I'm not saying they aren't doing good things, you're right, it's pretty good when the spooks keep each other and cybercriminals in check, see the article in OP, Apple's hardware backdoors (Operation Triangulation), and many other cases.
by orbital-decay
8/23/2026 at 3:57:58 PM
FSB? Oh you mean Russian “Federal Security Service” ?by atmosx
8/23/2026 at 5:17:42 PM
It's been a while since I thought about Front Side Busby _joel
8/23/2026 at 5:36:22 PM
As it says in the first line of the WP article: "Federal Security Service (FSB)"by jibal
8/23/2026 at 5:42:11 PM
The article is about a controversy involving allegations. There is plenty of evidence presented that the controversy and the allegations exist. (And if you dig into the links, there is plenty of evidence that the allegations are not without basis.)> “sources said”
Yes, that's how Wikipedia works. https://en.wikipedia.org/wiki/Wikipedia:Neutral_point_of_vie...
by jibal
8/23/2026 at 3:38:09 PM
Welcome to Wikipediaby DaSHacka
8/23/2026 at 5:27:45 PM
This makes me think whether the whole chain is an intelligence side business — sell cheap electronics for profit and at the same time own them too.by markus_zhang
8/24/2026 at 5:12:22 AM
Interesting how there is possibly a new category of residential proxy malware “automotive proxy malware”by camkego
8/24/2026 at 2:39:42 PM
This is just another mobile device. It even has a SIM card.by dolmen
8/23/2026 at 3:09:56 PM
> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unitHuh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?
by mschuster91
8/23/2026 at 4:00:14 PM
Wireless AA and CarPlay use a hotspot your car emits that your phone connects to and transfers the image/inputs/audio that wayby 306bobby
8/24/2026 at 9:00:08 AM
Got into a weird situation recently where my cheap android head unit was displaying Car Play from my phone, but (Google Maps) audio from my partner's.Directions weren't coming from my phone's speaker or the car, but testing audio in the Maps app did (from the car).
Still not sure what combination of connections it had managed to get itself into!
by scoot
8/23/2026 at 3:24:44 PM
Wireless CarPlay uses Bluetooth to exchange SSID and key info before switching over to WiFi for the duration of the session.by m-s-y
8/23/2026 at 7:17:35 PM
Wow that's cursed, never realized that's how it worked.by NewJazz
8/23/2026 at 9:40:46 PM
Cursed is exactly how I would describe it - because it works great until it doesn’t and it of course gives you zero clue why it won’t connect.by xp84
8/24/2026 at 2:04:20 PM
Anecdotally, I just got back from a holiday trip across Europe and crossed four international borders. At every single border crossing, my CarPlay session disconnected, and I had to toggle CarPlay off and back on in my phone settings to reconnect. Very strange, and I still have no idea what caused it.by NLMichel
8/23/2026 at 11:43:21 PM
It's a good idea actually, but it's also really complex to get right.Early version of Android Auto could transfer over USB 2.0 instead of Bluetooth, which works, but it's not near as high bandwidth.
by bluGill
8/24/2026 at 8:15:09 AM
> Early version of Android Auto could transfer over USB 2.0 instead of Bluetooth, which works, but it's not near as high bandwidth.This sentence doesn't make much sense - Auto (and CarPlay) still work in wired mode over USB 2.0 if the head unit supports it. They never worked over Bluetooth.
(And they use less than 15Mbps so USB 2.0s 480MBps are more than enough)
by izacus
8/24/2026 at 11:10:47 AM
They use Bluetooth to configure WiFi. Most people call that Bluetooth, but technically you are correct.by bluGill
8/23/2026 at 3:21:15 PM
The way I understand it, the connection is negotiated via BT, but then wifi is used for the fat data pipe to run the display.by dhc02
8/24/2026 at 2:55:11 PM
My car requires wired connectivity (USB) for Android Auto.by dolmen
8/24/2026 at 8:59:57 PM
For a decent amount of the older android / CarPlay usb implementations - you can also buy little WiFi / USB dongles that perfectly enable wireless CarPlay - I’ve used them now on a few vehicles and they have been perfect !by 3guk
8/23/2026 at 4:38:49 PM
They didn't run over BT. BT is used to initiate communication and share the password to a wifi-network. It then uses that Wi-Fi network for most communication, keeping the BT channel strictly for telephony.by alphager
8/23/2026 at 3:34:58 PM
I thought the latest Bluetooth protocols were basically designed to hand off to an ad-hoc Wi-Fi connection between the two devices after the initial handshake. (Might be an oversimplification of the real protocol)by StilesCrisis
8/23/2026 at 7:39:47 PM
It uses Bluetooth to stream audio, but everything else happens through a WiFi connection exposed by the car that the phone automatically pairs with after the Bluetooth handshake.by iamjackg
8/24/2026 at 3:03:58 AM
Not sure about CarPlay, but Android Auto connects via wifi to the head unit for the video feed.by russelg
8/24/2026 at 2:05:48 PM
Not sure about carplay, but Android Auto wireless uses wifi for the video stream.by deaton
8/23/2026 at 4:48:11 PM
They actually run over WiFi (WiFi direct IIRC) - Bluetooth is mostly just used as a setup handshake and to help the head unit decide which phone in the car should be the one connected.by izacus
8/23/2026 at 4:40:14 PM
> It cannot self-propagate to any Android-based head unitArticle does not say that.
by chrisjj
8/24/2026 at 12:51:16 AM
So? spicyjpeg is pointing out what is true, not just regurgitating TFA.by jibal
8/23/2026 at 4:56:57 PM
Headline really quite clearly implies it, though. I think the correction is apt.Bottom line is that lots of HN commenters here, as is our wont, will see this as a platform bug with a hated rival and not a bad third party integration that introduced vulnerabilities.
Like, if it was a Linux-based edge system from some fly-by-night contractor, would you be OK with a headline like "Malware infects Debian based refrigerators"? What'd Debian do?
by ajross
8/23/2026 at 6:32:20 PM
It’s no different than how the old Ford Sync or something else could have been compromised.The two big things here in my mind are:
1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out
2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW/Volvo/whoever
by MBCook
8/23/2026 at 7:51:10 PM
This is not Android Auto though, which is an entirely different product suite designed to connect a OEM infotainment system to an Android device owned by the vehicle operator. That protocol is proprietary, Google-owned and managed, not part of AOSP, and not available to the integrator of the software in question.The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software stack based on AOSP. It's not even "Android" in a product marketing sense.
Again, it's like blaming Debian because some loon stuffed it in a wifi NAS or whatever and put a backdoor into their UI. It's insane.
by ajross
8/23/2026 at 9:23:18 PM
Do you mean Android Automotive?by MBCook
8/23/2026 at 4:17:40 PM
It cannot self-propagate to any Android-based head unitRemember that not that long ago viruses spread through floppy disks.
Today, people share USB sticks full of music from one car to another all the time. They also bring their music from their home car to a rental car and back.
by reaperducer
8/23/2026 at 9:36:54 PM
I’ve never met anyone irl who used USB sticks full of music. I know the capability is there in most cars, just never seen it. It seems like Bluetooth capability and Spotify/Apple Music landed in mainstream cars too soon after “play MP3s from USB” was added, for that to catch on.by xp84
8/24/2026 at 2:16:40 AM
I did it for a few years, back when I had a new car with the capability but not a phone with a good mobile data plan.It had the benefit of an information center with physical buttons too, so I could navigate around my library without touch screen madness or voice commands constantly failing to understand band and song names.
by zdragnar
8/24/2026 at 12:10:24 AM
> I’ve never met anyone irl who used USB sticks full of music.I've been doing it for years, since it's so much more convenient than the alternatives: plug the stick into my car and I have my whole music library there and it Just Works.
by pdonis
8/24/2026 at 2:51:40 PM
We haven't met yet.We use an USB key full of audio books: Harry Potter saga and The Quest of Ewilan among others. The whole family is hooked.
The car UI is much more reliable (no phone to unlock by the copilot, no Bluetooth disconnect). The phone battery is spared for navigation purposes.
by dolmen
8/24/2026 at 1:10:26 PM
I have 256GB of FLAC in my car, and it's great.by creaturemachine
8/23/2026 at 11:19:16 PM
My hand is raised. I like having 8GB of music on an old (USB2 is fine) flash drive in my car as a fallback. On longer trips I'll hookup the Android Auto, but if I don't need maps and it's a quick ride, shuffle & repeat all enabled on the USB source.Sure beats the radio, which plays 2 songs and then 5 min of commercials/sweepers, and has the gall to run ads on the HD text transmission on FM designed for song information.
by briHass
8/23/2026 at 4:31:20 PM
Most people just bring their phone between cars for music.by charcircuit
8/24/2026 at 12:13:08 AM
My phone is much clunkier to use for this than a USB stick. Plus my phone can't store my whole music library (because there's too much other stuff already on it), whereas a single USB stick does it easily with plenty of room to spare.by pdonis
8/24/2026 at 4:04:05 AM
Phones can access the whole internet. A USB stick can't stream Spotify or connect to the cloud.by charcircuit
8/24/2026 at 1:58:07 PM
Which doesn't matter to me since the music I'm talking about is music I already have on the USB stick (because it's music I've collected over years and years of buying CDs, mostly before ways of streaming music over the Internet even existed), and I mostly want to listen to that. If I want something else, I can just use XM radio.by pdonis
8/24/2026 at 2:52:47 PM
You'll be surprised, but some places where a car can go have no phone connectivity.by dolmen