Android Auto (Google Assistant) vs Apple Carplay (Siri)

Grok joins ChatGPT and Perplexity on CarPlay

With the release of iOS 26.4 in late March, Apple enabled support for third-party AI chatbots in CarPlay. However, for the integration to work, the developers of those AI chatbots had to update their apps too.

OpenAI was first, making ChatGPT work in CarPlay in early April. Perplexity soon followed suit, and now Grok is the third AI chatbot you can talk to in CarPlay, as the Grok app for iOS has been updated with support for this feature.


 
Gemini starts replacing Google Assistant inside Android Automotive

This move hardly comes as a surprise. Google hinted at it back during an earnings call last year and then demoed it at Google I/O 2025. Also, the online giant has been investing so heavily in its AI system that it only makes sense for it to eventually replace the traditional Google Assistant.

And while the latter has come a long way over the years, it can still be quite rigid in its conversation and understanding, especially when it has to accept user commands and potentially interpret those to control actual car features. To be clear, this is Android Automotive we are talking about as opposed to Android Auto. The latter is the smart assistant you can cast on your car multimedia screen, while the former is actually an interface built into some modern cars.

Gemini should allow for much more natural conversation instead of memorizing specific commands. For instance, instead of saying something like “Set climate control to level 5,” the user might just say “Blast the AC for me!”

The new switch to Google Gemini seems to be kicking off with OTA updates on certain Volvo cars, like the EX30 electric SUV. Drivers have reported getting a polite pop-up to switch over to Gemini, but only if they want to, which is a nice touch. Also, if they do, Gemini is not super opposing, taking over the entire UI. Instead, it lives inside its own little “interactive pill” in the UI, waiting for a trigger word. There is also a nifty “Live” button that users can press and just have longer conversations with the AI without the need for trigger words.


 

Hackers infect Android car head units with proxy botnet malware - Bleeping Computer​


1787448232505.png

A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud.

Kaspersky researchers analyzed the malware and attributed the operation to the MoYu group, a threat actor previously associated with the BadBox malware botnet.

The researchers note that this is the first documented case of a malware infection chain specifically created for the targeted car head unit.

MoYu's operation targets systems from DoFun, a Chinese automotive software and hardware provider owned by Shenzhen Driving Control Technology Co., Ltd.

DoFun is an automotive software, cloud services, and hardware provider that sells generic Android-based head units, which act as the command center for a car's infotainment, navigation, and settings systems.

In June, Kaspersky researchers found a rogue APK file being downloaded from a legitimate DoFun system app, TWCore, which receives instructions through an MQTT server hosted at cardoor[.]cn.

The unknown app has no interface and is a piece of malware called JarService. When launched, the malware decrypts and executes a second-stage loader that establishes communication with a command-and-control (C2) server and downloads another encrypted payload.

The final payload periodically reports device information such as the model, display resolution, Wi-Fi SSID, and MAC address, and retrieves commands from the attackers.

The malware supports the following nine commands:

  1. return - Retrieves a specified value from Android’s SharedPreferences storage
  2. copy - Copies stored or downloaded content to the device clipboard
  3. http - Sends HTTP GET or POST requests and can save part of the response
  4. web - Opens a URL in a WebView and executes supplied JavaScript
  5. loadlib - Not fully implemented when Kaspersky published the report
  6. loadlib2 - Downloads and executes arbitrary code or additional modules
  7. loadlib3 - Not fully implemented when Kaspersky published the report
  8. deeplink - Opens a specified resource in the browser
  9. traceroute - Checks whether specified hosts are reachable using ICMP ping
Kaspersky says the malware does not interfere with driving or critical vehicle control systems, and appears designed for advertising fraud and turning internet-connected car head units into residential proxy nodes for monetization purposes.

Researchers discovered that the operator primarily loaded a reverse-proxy module named ‘zhima,’ which turns the head unit into a proxy botnet node, and also made web requests for click-fraud activity.

Kaspersky says it notified DoFun of its findings, and the Chinese firm replied that it resolved the problem.

BleepingComputer has contacted both companies with questions about the initial compromise vector, and we will update the article with the information once received.

 
Top
Sign up to the MyBroadband newsletter
X