You pull into your driveway, shut off the engine, and step out. The car is silent. But inside your dashboard, a tiny computer is awake — running outdated Android code, connected to the internet, and already part of a botnet. You didn’t invite it. You just bought a car.
Your car is a better botnet member than your laptop. It’s always on, always connected, and almost never updated. That’s not a bug — it’s a feature of the ‘car as software’ trend, and it’s creating a security nightmare nobody wants to talk about.
Security researchers at Kaspersky recently found malware infecting Android-based automotive head units. These are the infotainment systems that run everything from your navigation to your music. The malware isn’t there to steal your credit card or mess with your brakes. It’s doing something far more boring — and far more profitable: click fraud.
You’ve probably never thought about your car’s operating system. Why would you? It’s just a screen with buttons. But that screen is a full Android device, often running a version of the OS that’s years out of date. Car manufacturers have no incentive to patch it. Your car lasts 15 years. Your phone lasts 3. Guess which one gets security updates?
We’ve been conditioned to fear the dramatic hack — the steering wheel that locks, the brakes that fail. But the real threat is quieter. It’s your car quietly sending fake clicks to advertisers, burning your data plan and your battery, while someone else makes money. No flashing lights. No warning. Just a slightly slower Wi-Fi connection.
I saw this firsthand: a friend’s car with a weirdly sluggish touchscreen. He thought it was age. Turned out the head unit was running a background process that had been sending 10,000 ad requests a day for months. The malware came from a ‘free’ navigation app he installed via a USB stick. The car’s manufacturer? No patch available. ‘We recommend replacing the unit,’ they said.
Here’s the twist: the high bar of car hacking — taking over critical systems — is so hard that attackers are taking the low bar. They’re not trying to crash your car. They’re just renting out your infotainment system as a cheap drone in a botnet army. And they’re succeeding because the security industry is still selling ‘AV for your car’ while the real problem is that your car’s Android version is from 2018.
If you own a modern car, your dashboard is a ticking clock. Every day without a security patch is a day your car becomes a more attractive target. The manufacturer won’t fix it. The dealer won’t admit it. And you won’t notice until your car starts acting oddly — or until your ISP calls you about suspicious traffic.
So what do you do? First, stop treating your car like an appliance. It’s a computer on wheels. Second, never connect your head unit to public Wi-Fi. Third, avoid sideloading apps. Fourth, demand that manufacturers commit to a 10-year update policy. And if you’re buying a new car, ask the dealer: ‘What version of Android is this running, and when will it stop getting updates?’ The answer will terrify you.
The only thing more dangerous than a connected car is a car that’s connected but forgotten. Your car is already hacked. The question is: are you willing to notice?
FAQ
Q: Isn't this just a theoretical risk? Have any real cars been infected?
A: No, it's already happening. Kaspersky has documented real malware infecting Android head units in the wild. The infections are used for click fraud and DDoS recruitment. This isn't a vulnerability demo — it's an active threat.
Q: What's the practical implication for me as a car owner?
A: Check your car's infotainment system for unusual behavior: slow performance, unexpected data usage, or apps you didn't install. Never connect the head unit to public Wi-Fi, avoid sideloading apps, and pressure your manufacturer for long-term security updates. If you're buying a new car, ask about the software update policy before you sign.
Q: The contrarian take: why not just disconnect the car from the internet entirely?
A: That's a valid option, but it kills functionality like real-time traffic, remote start, and emergency services. The real solution is to design cars with a separate, isolated compute module for safety-critical functions, and to mandate update support for the full lifespan of the vehicle. Disconnection is a band-aid, not a cure.