The article does not make it particularly clear, but the malware in question is delivered through official first-party OTA updates on cheap Chinese aftermarket head units that happen to run Android. It cannot self-propagate to any Android-based head unit, nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit. This seems to be a very similar situation to that of cheap generic Android TV streaming boxes, which often come pre-infected from the factory with residential proxies and other malware as well; most of the infrastructure is likely shared.
Why do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor's update server was compromised? If so why don't they just say so.
Cheap Android phones and tables often have built-in advertisement from manufacturer. One example of such software, it creates a window with Google Ads on top of browser window. The window is shown only when the browser is active to make it look like the ads is a part of the site. The ads appears only couple weeks after activation so that the user thinks it is a result of installation of some app and Youtube reviewers do not notice existence of malware. The adware consults a remote config which defines in what countries it should work. Another adware component automatically downloads and re-installs it if it is deleted.
I found all these details through examining the official firmware image and reverse engineering.
I don't remember if I reported Google Ads id to Google. It is interesting that Google doesn't notice and care about such use of their products.
there is the problem. We don't know what country is in question. There are some countries where the truth is not a defense against libel. Thus, depending on where the author is from, or for that matter the publisher or other people who might happen to be in the chain, there could be a libel case if the truth was stated.
Indeed this is an odd disclosure and I am not familiar with past posts by them.
Moreover, no CVE is associated with this claimed vulnerability. It's not even stated which Android version or automotive head-unit variant version is affected.
Wikipedia's source policy makes it nearly impossible to refer to anything that is not in the media, and any sensitive article has to use weasel words like this. Are you just noting the issue with the article, or actually doubting that Kaspersky Labs is a de-facto FSB branch since at least 2015?
Up until 2015 all was good with Kaspersky. But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government. Over the next years Kaspersky opened a bunch of 'transparency centers' offering full code audits and inspection, relocated their core infrastructure and customer data to Switzerland - subsequently falling under their data regulations, and so on.
And if they were in any way affiliated with the Russian (or any) government, there seems no logical reason they'd publicly share their findings of the NSA malware, let alone the other transparency actions. Their data would be vastly more valuable if kept secret, because it'd open the door to greater exploitation of US cyber activities and being able to covertly secure desired systems. Instead their actions benefited everybody, but obviously embarrassed the NSA and as a result the US.
KL is a credible shop, they basically founded the modern anti-malware industry and pioneered most basic techniques in the 90's and early 2000's, together with some of their then-rivals like Dr. Web. There's a reason they were trusted, and there's a reason they tried to deny their takeover, they have a genuinely earned reputation.
This doesn't mean they aren't a FSB branch, in the same way e.g. NSO Group is a Mossad branch, with one difference that KL sell themselves as defensive and NSO Group doesn't. It was confirmed by KL employees in their socials that the management has been largely taken over by actual FSB officers. Some have left the company out of protest because they felt it's getting raided (отжим in Russia is not like your usual corporate takeover...). It's impossible to link it now as most of these people are living abroad since 2022 or earlier and either removed all their stuff or their socials entirely, some have renounced their citizenship by this point. But as a general rule, assume every important business in Russia is taken over by the government since 2022, either directly or indirectly. In 2026, whitewashing Kaspersky Labs of all companies is weird.
>But then in February of that year they posted a detailed writeup on malware created by the Equation Group, the NSA. [1] Within a month US media outlets, relying on anonymous sources, began posting endless claims that Kaspersky was a part of the Russian government
There was also a war happening, which you aren't saying.
>Over the next years Kaspersky opened a bunch of 'transparency centers' offering full code audits and inspection, relocated their core infrastructure and customer data to Switzerland - subsequently falling under their data regulations
The audits are to check the checkboxes, they mean very little. Plenty of former Russian companies that moved abroad are keeping ties with the developers at home, despite all audits, fronting campaigns, and otherwise pretending they aren't (not all though, others did actually migrate).
>if they were in any way affiliated with the Russian (or any) government
I mean, YK himself is KGB and there are no former ones, as they say. KL is one of the main government cybersec contractors, for starters. In a country where the government controls most of the economy they are producing critical industrial security systems like data diodes and secure gateways with their own OS, you can go to their site and look at all this yourself.
Cybersec industry in general is heavily affiliated with their respective governments, I don't think it's a secret for anyone and denying this is just silly. Some of them are more than others.
>there seems no logical reason they'd publicly share their findings of the NSA malware ... Their data would be vastly more valuable if kept secret, because it'd open the door to greater exploitation of US cyber activities and being able to covertly secure desired systems.
What? This doesn't make any sense, sorry. Security agencies usually publish or leak actions of their adversaries.
>Instead their actions benefited everybody
Did their inaction benefited anyone? RuNet which has been great got basically destroyed and turned into a safe haven for half of world's cybercriminals on their proud watch, and they aren't writing anything on this. They serve as part of their "roof".
Note I'm not saying they aren't doing good things, you're right, it's pretty good when the spooks keep each other and cybercriminals in check, see the article in OP, Apple's hardware backdoors (Operation Triangulation), and many other cases.
Kaspersky isn't just a credible lab. They were, and remain, the best antivirus provider, by their results on basically any and all test batteries. Similarly their founder (Eugen Kaspersky - I assume who you are referencing with "YK") has never worked for the KGB. He was educated at at a KGB affiliated school and afterwards went to work for the Ministry of Defense. Within a few years the USSR collapsed and he then went, and stayed, within the private sector.
But most importantly - companies (let alone other governments) providing detailed information on how other governments' cyber operations is most certainly not a thing that's done. That report I linked to is not just speaking in evidence free vagaries of the geopolitical 'leak' type you are alluding to. It provided extensive operational details and includes things such as even naming a specific driver as which is implied as being a Windows backdoor with plausible deniability.
They chose to publish it letting the NSA know exactly which methods had been discovered, how they were discovered, and even exact versions they detected and potentially on exactly which machines (if the NSA salts binaries), given that the hash/date info were also provided. All of this is immensely valuable information that could have been both weaponized and 'defensized' for Russian cyber purposes. Providing it helped the NSA more than anybody. Outside of Trumpian 5d chess, there's no rational explanation for this, if one assumes they are in any meaningful way controlled by the Russian government.
The article is about a controversy involving allegations. There is plenty of evidence presented that the controversy and the allegations exist. (And if you dig into the links, there is plenty of evidence that the allegations are not without basis.)
> nor does it affect Android Auto which is a "dumb" screen mirroring protocol with the bulk of the software running on the connected phone rather than the head unit
Huh, how does that work anyway? And while we're at it, Apple CarPlay as well? Both can run wirelessly via Bluetooth, but BT is nowhere near capable enough to stream full bandwidth video?
Anecdotally, I just got back from a holiday trip across Europe and crossed four international borders. At every single border crossing, my CarPlay session disconnected, and I had to toggle CarPlay off and back on in my phone settings to reconnect. Very strange, and I still have no idea what caused it.
> Early version of Android Auto could transfer over USB 2.0 instead of Bluetooth, which works, but it's not near as high bandwidth.
This sentence doesn't make much sense - Auto (and CarPlay) still work in wired mode over USB 2.0 if the head unit supports it. They never worked over Bluetooth.
(And they use less than 15Mbps so USB 2.0s 480MBps are more than enough)
They didn't run over BT. BT is used to initiate communication and share the password to a wifi-network. It then uses that Wi-Fi network for most communication, keeping the BT channel strictly for telephony.
I thought the latest Bluetooth protocols were basically designed to hand off to an ad-hoc Wi-Fi connection between the two devices after the initial handshake. (Might be an oversimplification of the real protocol)
It uses Bluetooth to stream audio, but everything else happens through a WiFi connection exposed by the car that the phone automatically pairs with after the Bluetooth handshake.
For a decent amount of the older android / CarPlay usb implementations - you can also buy little WiFi / USB dongles that perfectly enable wireless CarPlay - I’ve used them now on a few vehicles and they have been perfect !
They actually run over WiFi (WiFi direct IIRC) - Bluetooth is mostly just used as a setup handshake and to help the head unit decide which phone in the car should be the one connected.
Headline really quite clearly implies it, though. I think the correction is apt.
Bottom line is that lots of HN commenters here, as is our wont, will see this as a platform bug with a hated rival and not a bad third party integration that introduced vulnerabilities.
Like, if it was a Linux-based edge system from some fly-by-night contractor, would you be OK with a headline like "Malware infects Debian based refrigerators"? What'd Debian do?
It’s no different than how the old Ford Sync or something else could have been compromised.
The two big things here in my mind are:
1. Android Automotive has gotten very popular since it provides so much and writing your own OS is very very hard and expensive as so many car makers found out
2. Aftermarket head units often use it (see #1) so it’s likely far easier to get out there than if you had to compromise Ford/VW/Volvo/whoever
This is not Android Auto though, which is an entirely different product suite designed to connect a OEM infotainment system to an Android device owned by the vehicle operator. That protocol is proprietary, Google-owned and managed, not part of AOSP, and not available to the integrator of the software in question.
The actually vulnerable system is a custom vehicle head unit that merely happens to be running a software stack based on AOSP. It's not even "Android" in a product marketing sense.
Again, it's like blaming Debian because some loon stuffed it in a wifi NAS or whatever and put a backdoor into their UI. It's insane.
It cannot self-propagate to any Android-based head unit
Remember that not that long ago viruses spread through floppy disks.
Today, people share USB sticks full of music from one car to another all the time. They also bring their music from their home car to a rental car and back.
I’ve never met anyone irl who used USB sticks full of music. I know the capability is there in most cars, just never seen it. It seems like Bluetooth capability and Spotify/Apple Music landed in mainstream cars too soon after “play MP3s from USB” was added, for that to catch on.
I did it for a few years, back when I had a new car with the capability but not a phone with a good mobile data plan.
It had the benefit of an information center with physical buttons too, so I could navigate around my library without touch screen madness or voice commands constantly failing to understand band and song names.
> I’ve never met anyone irl who used USB sticks full of music.
I've been doing it for years, since it's so much more convenient than the alternatives: plug the stick into my car and I have my whole music library there and it Just Works.
My hand is raised. I like having 8GB of music on an old (USB2 is fine) flash drive in my car as a fallback. On longer trips I'll hookup the Android Auto, but if I don't need maps and it's a quick ride, shuffle & repeat all enabled on the USB source.
Sure beats the radio, which plays 2 songs and then 5 min of commercials/sweepers, and has the gall to run ads on the HD text transmission on FM designed for song information.
My phone is much clunkier to use for this than a USB stick. Plus my phone can't store my whole music library (because there's too much other stuff already on it), whereas a single USB stick does it easily with plenty of room to spare.
Which doesn't matter to me since the music I'm talking about is music I already have on the USB stick (because it's music I've collected over years and years of buying CDs, mostly before ways of streaming music over the Internet even existed), and I mostly want to listen to that. If I want something else, I can just use XM radio.