Remix.run Logo
kotaKat 6 hours ago

It seems like this exploit is targeting those that keep their phones tethered for connectivity outwards or hooked a USB modem or a SIM card into a cell-equipped headunit.

The only valuable thing there is the relatively 'clean' mobile connection... and this malware's dropping a residential proxy endpoint on the headunit to take advantage of it. Bonus points if the headunit is always connected and always powered up to a +12v rail in the car, that's free and always-on real estate!

brookst 6 hours ago | parent [-]

Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition / accessory mode turns off, and go completely power-off 30-ish minutes later.

Otherwise any car sitting unused for a week or two would have a dead battery.

Zigurd 5 hours ago | parent | next [-]

I learned that not all electronics goes into low power mode even when designed to run off a car battery, from using a cheap Bluetooth OBDII dongle.

smilespray 4 hours ago | parent [-]

If that was one of those ELM327 dongles, yes they have 12V and are known to drain your battery. They're only meant for short diagnostic runs.

olyjohn 5 hours ago | parent | prev | next [-]

They are always wired to battery power though. The point is that it could look powered off, and still be running a proxy.

lmz 2 hours ago | parent [-]

You would hope that the ignition switch really cuts the power to the head unit when it is switched to off.

carstenhag 2 hours ago | parent [-]

No you wouldn’t, because then you always have a cold boot of the headunit, even if you just accidentally hit the ignition. Users want the head unit to resume within a few seconds. Just like their phone.

kotaKat 4 hours ago | parent | prev [-]

Some of these Android units also double as DVRs and dashcam recorders (parking mode!) as well so may be hooked onto the normal +12v rail.