Hackers infect Android car infotainment screens through malicious software updates

Hackers are increasingly targeting Android-based car infotainment systems by abusing built-in software update mechanisms. Researchers discovered malware that can silently enter connected car screens through the trusted update process, turning features designed for maintenance into an entry point for cyberattacks.

Hackers Infect Android Car Screens Through Malicious Software UpdatesHackers Infect Android Car Screens Through Malicious Software Updates

The malware can collect device information, download additional payloads, display fraudulent advertisements, generate fake clicks, and even turn infected car screens into proxy nodes. The campaign has been linked to activity associated with the MoYu Group and BADBOX, highlighting how connected vehicles and Android head units are becoming attractive targets for cybercriminals.

This incident highlights the growing importance of automotive cybersecurity and Android device protection. Vehicle manufacturers should ensure that software updates use strong package verification and secure delivery channels, while users should install updates only from trusted manufacturer sources. As connected car technology expands, protecting infotainment systems from malware is becoming an important part of overall digital security.
 
NPAV Endpoint Security, help detect fileless malware, block malicious scripts, and protect users from credential-stealing attacks delivered through fake software downloads.