12:01 PM

Counterclank Apps To Remain In Android Market

Some security experts call Counterclank apps malware, not adware. But Google says the apps comply with the company's terms of service.

10 Great Android Collaboration Apps
10 Great Android Collaboration Apps
(click image for larger view and for slideshow)
Google said a controversial set of advertising-supported Android apps will remain in its official Android Market, because they comply with the company's terms of service. The 13 apps in question, which Google said have been collectively downloaded up to 5 million times, use adware software known as Counterclank.

Symantec first sounded the alarm over Counterclank last week, labeling the software--which is part of such apps as Counter Strike Ground Force, Balloon Game, and Sexy Girls Puzzle--as malware. But rival mobile security firm Lookout published its own analysis of the Counterclank software, also known as the Apperhand software development kit, and came to a different conclusion, instead labeling it as adware.

Notably, Lookout found that although Apperhand was "aggressive" and perhaps demonstrated "bad form"--for example because it can change a smartphone browser's homepage, add arbitrary bookmarks, and place a search icon on the home screen--the software didn't exhibit signs of actually being malicious. Rather, it had all of the classic signs of being part of an adware platform, which some software developers use to earn money from their applications. In the case of Apperhand, that compensation appears to be largely based on driving the users of their apps to specified search engines.

[ Adware recently plagued Google and Facebook sites. Adware Reborn As Facebook Theme Software. ]

Symantec also said that it had alerted Google to the presence of Counterclank in 13 apps sold via the Android Market. But, it said, "Google replied quickly informing us the applications met their terms of service and they will not be removed."

If the "is it adware, or is it malware?" debate sounds familiar, that's because five years ago, controversy raged over how to classify advertising-supported software on Windows PCs. Although its purveyors often labeled their software as adware, security and antivirus companies more often than not labeled it as malware--in part because some so-called adware was actually malicious--and typically blocked both. Some pundits, meanwhile, helpfully just classifed it all as badware.

Likewise, in response to Lookout's analysis of Counterclank, Symantec this week said that regardless of whether the software counts as malware or adware, the bigger question is: Who wants it on their device?

"The situation we find ourselves in is similar to when adware, spyware, and potentially unwanted applications first made appearances on Windows," read a blog post from the Symantec Security Response Team. "Many security vendors did not initially detect these applications, but eventually, and with the universal approval of computer users, security companies chose to notify users of these types of applications."

"Due to the combined behavior of the applications, negative feedback from users who installed the applications, and the fact that previous applications (Android.Tonclank) using this code were initially suspended from the Google Market, we chose to notify users of Counterclank," said Symantec.

Interestingly, Counterclank is a new version of the Tonclank--aka Plankton--software development kit that first began appearing in Android apps this past summer. Although Google initially suspended apps that contained Tonclank, after further review it reinstated them in the Android Market.

Please join us on Feb. 15 for the InformationWeek & Dark Reading virtual event Clouds, Outsourcing, And Security Services: Making Providers Part of Your IT Security Strategy. When you attend, you will be able to access live and on-demand webcast presentations as well as virtual booths packed with free resources, and you can also be eligible to win great prizes! (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Current Issue
Dark Reading Tech Digest September 7, 2015
Some security flaws go beyond simple app vulnerabilities. Have you checked for these?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-06
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 21335999.

Published: 2015-10-06
Bluetooth in Android before 5.1.1 LMY48T allows attackers to remove stored SMS messages via a crafted application, aka internal bug 22343270.

Published: 2015-10-06
mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22954006.

Published: 2015-10-06
The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23050463.

Published: 2015-10-06
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23213430.

Dark Reading Radio
Archived Dark Reading Radio
What can the information security industry do to solve the IoT security problem? Learn more and join the conversation on the next episode of Dark Reading Radio.