Proxy botnet malware spread via legitimate update apps on Android
Source headline: Hackers infect Android car head units with proxy botnet malware
Intelligence Summary
A supply-chain attack is targeting Android-based car head units. The malware is spread using a legitimate device-update app. Compromised devices are reportedly enlisted in a proxy botnet. The same devices may also be used for ad fraud. Users of affected Android head units should disable or remove the suspicious update pathway and confirm device updates from trusted sources.
Recommended Action
Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.