
Findings and evidence
Kaspersky reconstructs an Android malware chain delivered through built-in updaters on automotive head units. The reported objectives include advertising fraud and proxy activity, with the investigation connecting the infection path to the device’s firmware software ecosystem.
Why it matters
Mobile evidence is not limited to handsets. Device model, firmware revision, update provenance and network observations all help distinguish a user-installed app from a problem upstream in the supply chain.
Scope and limits
This research concerns Android infotainment hardware and the observed campaign. It does not demonstrate compromise of vehicle safety controls or every head unit of a given brand.
Primary source
Kaspersky / Securelist: original publication. Source published 2026-08-21. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.