In June 2026, we discovered an unusual new piece of malware targeting… Android-based car head units. This is the first documented case of malware being delivered to automotive head units via an automatic firmware-update service. We’ve covered automotive cyber-incidents many times before, but those were generally related either to data leaks in manufacturers’ digital infrastructure, or to security researchers’ experiments. This case, however, involves malware that cybercriminals are distributing in the wild. Their goals are ad fraud and creation of a proxy botnet made up of infected automotive head units. In this article, we explain what a head unit is, how exactly attackers infect these devices, and what this could mean for drivers. What is a car head unit (HU)? First, let’s clarify what a car head unit actually is. The term may sound technical, but in reality, most drivers interact with one every time they use their car. A head unit is the vehicle’s infotainment system — usually centered around a display used to control navigation, music, and other vehicle functions. In modern cars, head units are often connected to the internet. Manufacturers frequently use Android as the operating system for their head units — in part for simplicity’s sake: Android is designed to support automotive head-unit usage cases, bringing a number of advantages: - extensive options for customizing the interface; - easy app development; - the ability to add one’s own system apps and components; - a large existing app ecosystem. However, those same advantages also create risks — because the apps involved may be malicious rather than legitimate. And that’s what’s happened here: using a malicious application, attackers have made cars part of a botnet. Here’s how… How do attackers infect car head units, and what malware do they use? First, it should be noted that this