Comment by kotaKat

10 hours ago

It seems like this exploit is targeting those that keep their phones tethered for connectivity outwards or hooked a USB modem or a SIM card into a cell-equipped headunit.

The only valuable thing there is the relatively 'clean' mobile connection... and this malware's dropping a residential proxy endpoint on the headunit to take advantage of it. Bonus points if the headunit is always connected and always powered up to a +12v rail in the car, that's free and always-on real estate!

Head units aren’t always-on. Typically they go into a low power standby 2-5 minutes after ignition / accessory mode turns off, and go completely power-off 30-ish minutes later.

Otherwise any car sitting unused for a week or two would have a dead battery.

  • I learned that not all electronics goes into low power mode even when designed to run off a car battery, from using a cheap Bluetooth OBDII dongle.

    • A lot of older cars didn't turn off their OBD port, have their headunits go into standby, or even turn off the cigarette lighter port. Early OBD ports connected to dealer computers for a few minutes, not an always on dongle. Plain headunits just play music, what could they possibly accomplish by staying on when you turn off the car? It was a convenience having the cigarette outlet left powered so you could light a cigarette without turning on the car. Other than maybe a bag phone, what would you possibly plug into that?

    • If that was one of those ELM327 dongles, yes they have 12V and are known to drain your battery. They're only meant for short diagnostic runs.

  • They are always wired to battery power though. The point is that it could look powered off, and still be running a proxy.

  • Some of these Android units also double as DVRs and dashcam recorders (parking mode!) as well so may be hooked onto the normal +12v rail.