
highMalware
Supply-Chain Attack Uses Legitimate Update App to Infect Android Car Head Units with Proxy Botnet Malware
A supply-chain attack targeting Android-based car head units is leveraging a legitimate device-update app to distribute malware that turns compromised devices into a proxy botnet or uses them for ad fraud. The attack was reported on August 22, 2026, and affects users globally, though specific regions are not disclosed. The malware is delivered during the update process, potentially degrading device performance, consuming data, and exposing users to further malicious activity. No specific patch is available; users and manufacturers are advised to audit update channels and monitor for unusual network behavior.
BleepingComputer2 min read