Cars Have Joined The Android Malware Economy
For years, we’ve described modern vehicles as computers on wheels. Most people nod in agreement and move on. But that description is becoming more important than people realize. Security leaders need to pay attention to this emerging risk.
Recent research highlights malware that was built specifically to target Android-powered vehicle infotainment systems, marking a notable evolution in the connected vehicle threat landscape. The obvious focus is understandably on what this means for automakers and consumers, but enterprise security leaders should also take notice because the significance of this development isn’t that vehicles have suddenly become vulnerable. We’ve known for years that connected vehicles introduce cybersecurity risks. The significance is that attackers are beginning to treat vehicle platforms as just another computing device that they can target.
The Connected Vehicle Threat Model Is Progressing
Historically, many of the attacks involving connected vehicles have focused on adjacent systems. Researchers demonstrated how vulnerabilities in customer-facing applications, APIs, and cloud services could allow attackers to send commands to vehicles while other attacks required physical proximity and specialized tools to gain access to vehicle functions. These incidents highlighted the risks associated with connected vehicles, but they rarely involved malware designed specifically for the vehicle itself.
The latest research represents a meaningful shift. Instead of targeting vehicle management platforms or connected services, attackers have developed malware for the infotainment system itself, meaning they are targeting one of the vehicle’s most visible and capable computing environments.
Today’s campaign appears focused on botnet activity while tomorrow’s objectives may be different and security leaders should pay attention to the trend, not the specific malware.
Your Employees Have Cars. Are Your Business’ Mobile Devices Connected To Them?
Many organizations still view connected vehicle security as something that primarily concerns automotive companies. But that view ignores employees who connect mobile devices to vehicles through Bluetooth, USB connections, mobile applications, and cloud-based services. Fleet operators, service organizations, utilities, transportation providers, and enterprises with vehicle-dependent workforces continue expanding their reliance on connected vehicle technology. The result is an ecosystem where vehicles, mobile devices, applications, and enterprise data are more interconnected.
When another connected device enters that ecosystem, security leaders should ask:
-
- What happens if the device becomes compromised?
- How would we detect malicious activity?
- Could malware move between connected systems?
- What visibility do we have into that device and the risks associated with it?
Those are common questions when discussing laptops, smartphones, IoT devices, and operational technology. Connected vehicles now deserve similar scrutiny.
The Bigger Concern Isn’t The Vehicle
The immediate concern raised by this malware is not necessarily that attackers will gain complete control over vehicles, though that is certainly an issue for your employees’ safety. The bigger problem is that connected vehicles are increasingly running embedded operating systems that share characteristics with technology platforms that security teams already struggle to defend, such as IoT or OT devices. And in this case, these vehicles also share similarities with 3rd parties (contractors, OEMs, vendors) have systems connected to the enterprise as security analysts have no means to control.
Android malware is nothing new. Security teams have spent years dealing with threats targeting mobile operating systems. The emergence of Android-based vehicle malware suggests attackers increasingly view vehicles as another extension of the connected technology landscape rather than a separate category.
That creates new questions for security analysts:
-
- Could malware residing on a connected vehicle attempt to interact with a mobile device connected through Bluetooth or USB?
- Could organizations detect that activity?
- Are mobile security controls sufficiently mature to identify suspicious behavior originating from nontraditional endpoints?
Today, these questions remain largely theoretical because we haven’t seen a lateral attack of this nature yet. But security leaders should not dismiss this scenario as the industry has repeatedly seen attackers expand from one platform to adjacent systems once a foothold is established. Raise your hand if, before 2025, you thought you could bypass EDR and ransomware desktops from a webcam.
DON’T PANIC! But Review Your Risks, Please.
Organizations do not need to overhaul their security programs because of a single malware family. They should, however, revisit three assumptions.
-
- Include connected vehicles in threat modeling exercises where appropriate, especially for organizations with vehicle fleets or employees who frequently connect corporate devices to vehicles. This should include employees who travel and rent cars.
- Ensure that mobile security controls can identify malware and suspicious activity on corporate and BYOD mobile devices before it reaches enterprise applications, data, or cloud services.
- Evaluate connected vehicles as part of a broader ecosystem of business technology rather than treating them as isolated assets.
This new Android malware signals that connected vehicle security is moving from theoretical discussions toward practical risk management.
Let’s Talk
If you’re assessing how connected vehicles, EV infrastructure, and emerging transportation technologies could affect your organization’s risk posture, review Forrester’s connected vehicle research or schedule an inquiry or guidance session to discuss further.