Daily Security Intel

Archives
Log in
Subscribe
August 23, 2026

[SecurityIntel] 23 Aug | Android Car Head Units Hit By Supply-Chain Botnet

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Sunday, August 23, 2026

INTEL CONFIDENCE  94%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Android Car Head Units Hit By Supply-Chain Botnet

CRITICAL

5

C2 IPs

7

OTX IOCs

4

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by a sophisticated supply-chain attack targeting Android-based automotive head units, which leverages compromised update applications to recruit devices into a proxy botnet. Concurrently, the financial sector faces an onslaught of advanced banking trojans, with Manic, Grandoreiro, and ToxicPanda 2.0 expanding their global footprint. Additionally, securing Windows named pipes remains a critical priority to prevent local privilege escalation and lateral movement stemming from weak interprocess communication access controls.

■ CRITICAL STORIES

HIGH#1

Hackers infect Android car head units with proxy botnet malware

Threat actors compromised a legitimate device-update application to distribute proxy botnet and ad fraud malware to Android-based vehicle infotainment systems, demonstrating a highly targeted supply-chain vector.

CRITICAL#2

Named Pipes Under Attack: Securing Windows Interprocess Communication

Weak default access controls on Windows named pipes allow untrusted processes to communicate with privileged services, facilitating local privilege escalation and lateral movement.

HIGH#3

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Active campaigns leveraging advanced banking trojans and spyware are targeting financial institutions and consumers across Latin America, Europe, and global markets.

INFO#4

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

ByteDance-owned TikTok settled a massive federal lawsuit over child privacy violations, underscoring ongoing regulatory scrutiny and data protection compliance risks for mobile platforms.

■ CVEs IDENTIFIED

[CVE-TBD]

Android Car Head Unit Update App — Supply-chain malware delivery via legitimate update mechanism

High

[CVE-TBD]

Microsoft Windows (Named Pipes) — Privilege escalation via weak interprocess communication access controls

Critical

[CVE-TBD]

Android OS (ToxicPanda/Manic/Grandoreiro) — Banking trojan infection and credential theft via malicious packages

High

■ THREAT ACTORS

Grandoreiro Operators

Cybercrime Group

Conducting persistent banking trojan campaigns targeting Latin America and Europe

ToxicPanda Operators

Cybercrime Group

Deploying expanded ToxicPanda 2.0 banking malware for financial fraud

Unknown (Android Supply Chain)

Cybercrime Group

Compromising legitimate Android device-update apps to build proxy botnets

■ ATT&CK TTPs

T1195.002
Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Malware distributed via legitimate Android device-update application
T1559.001
Inter-Process Communication: Component Object Model and Distributed COM | Exploiting weak Windows named pipe access controls
T1055
Process Injection | Banking trojans injecting into legitimate processes or abusing accessibility services
T1114
Email Collection | Spyware-equipped banking trojans harvesting credentials and user data
T1090
Proxy | Infected Android head units acting as nodes in a proxy botnet

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Microsoft Windows (Named Pipes) — Weak access controls allow privilege escalation (PE) via untrusted IPC exploitation — BleepingComputer

[P1 PATCH NOW]≤24h

Android Car Head Unit Update Mechanism — Vulnerable to supply-chain malware injection enlisting devices in proxy botnets — BleepingComputer

[P2 PATCH NOW]≤72h

Android Mobile Devices — Targeted by active banking trojans (Manic, Grandoreiro, ToxicPanda 2.0) stealing credentials — SecurityWeek

■ RECOMMENDED ACTIONS TODAY

1[P1] Audit and restrict access permissions on Windows named pipes using Endpoint Verification and strict DACLs to prevent local privilege escalation.
2[P1] Implement strict supply-chain verification and code-signing checks for Android car head unit firmware and application updates.
3[P2] Deploy mobile threat defense (MTD) solutions on Android devices to detect and block banking trojans like Manic, Grandoreiro, and ToxicPanda 2.0.
4[P2] Restrict unnecessary outbound network connections from Android-based IoT and automotive systems to prevent proxy botnet enrollment.
5[P3] Review data privacy policies and age-verification mechanisms on consumer-facing applications to ensure compliance with child privacy laws.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 24 Aug | ToxicPanda Android Malware Abuses VPN Permissions Older → [SecurityIntel] 22 Aug | GitLab CVE-2026-19478 Under Active Exploitation
Powered by Buttondown, the easiest way to start and grow your newsletter.