Important note: The 10% of this talk was showed for first time at Re//verse Conference 2025 as a lightning talk. In that moment, the 5% of the discovered RTOS was reversed. During the 2025, this new RTOS (iRTOS) was reversed at 100% and an major bug was discovered in the bootloader process. Description: After an extensive hardware hacking and reverse engineering effort on a Kia head unit, a previously unknown RTOS was discovered. The entire RTOS was analyzed, leading to the identification of a critical vulnerability. In the third stage of the secure-bootloader process, the head unit images undergo no integrity verification. This flaw makes it possible to inject arbitrary PNG files into the firmware, disrupting the entire boot sequence and ultimately enabling a full defacement of the Kia head unit. Leveraging this weakness, a QR-code phishing attack can be executed, highlighting the severity of what appears to be a simple bug. In addition, the talk presents several other vulnerabilities uncovered in this newly discovered RTOS, named iRTOS. This talk envolve a complete hacking process with hardware hacking, software reverse engineering, graphic design, and malware development.