Podcast Episode
When the Automotive Update Path Becomes the Attack Path

About this episode
The most revealing automotive malware cases do not always begin by exploiting an unknown vulnerability. Sometimes they begin with software that the vehicle already trusts.
In this episode, we examine a malware infection chain targeting Android-based automotive head units. At its centre was TWCore, a legitimate system application used for analytics and software updates. Instructions received through an MQTT broker told the application which APK packages to download and install. A parameter called installNotExists allowed software that was not already present on the device to be introduced, including JarService, a dropper that loaded further malicious components.
The observed activity focused on ad fraud, reverse-proxy services and botnet-like capabilities. However, the more important cybersecurity lesson concerns authority. The attackers did not first need to defeat the local installation model. A trusted component already possessed the permissions required to introduce executable software.
We explore why encrypted communications, authenticated servers and signed packages are not enough when the update architecture cannot independently verify that a specific artefact is authorised for the vehicle, product variant and approved software baseline.
The discussion then moves to the operational decisions. How should manufacturers respond when telemetry is incomplete? Should they disable an update service, isolate the backend or wait for stronger evidence? How can they investigate affected vehicles without creating new availability or support risks? And what prevents a compromise in the infotainment domain from reaching gateways or safety-critical systems?
The episode concludes with a practical assurance model covering release manifests, package authorisation, runtime inventory, backend monitoring, least privilege and architectural containment.
Cybersecurity Under Pressure explores real attacks, their operational consequences and the engineering decisions required to protect cyber-physical products.
Websitehttps://cybersecurityunderpressure.com
Telegramhttps://t.me/cybersecurityunderpressure