← NEWS & INSIGHTS

NEWS / RESEARCH & ANALYSIS

Android head-unit malware expands the mobile forensic perimeter

Kaspersky reconstructs an Android malware chain delivered through built-in updaters on automotive head units.

Source published 2026-08-21Mobile forensicsResearch briefing
Original publication preview: Android head-unit malware expands the mobile forensic perimeter
Kaspersky / Securelist ↗

Findings and evidence

Kaspersky reconstructs an Android malware chain delivered through built-in updaters on automotive head units. The reported objectives include advertising fraud and proxy activity, with the investigation connecting the infection path to the device’s firmware software ecosystem.

Why it matters

Mobile evidence is not limited to handsets. Device model, firmware revision, update provenance and network observations all help distinguish a user-installed app from a problem upstream in the supply chain.

Scope and limits

This research concerns Android infotainment hardware and the observed campaign. It does not demonstrate compromise of vehicle safety controls or every head unit of a given brand.

Primary source

Kaspersky / Securelist: original publication. Source published 2026-08-21. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC