Risk
2/1/2012
12:01 PM
50%
50%

Counterclank Apps To Remain In Android Market

Some security experts call Counterclank apps malware, not adware. But Google says the apps comply with the company's terms of service.

10 Great Android Collaboration Apps
10 Great Android Collaboration Apps
(click image for larger view and for slideshow)
Google said a controversial set of advertising-supported Android apps will remain in its official Android Market, because they comply with the company's terms of service. The 13 apps in question, which Google said have been collectively downloaded up to 5 million times, use adware software known as Counterclank.

Symantec first sounded the alarm over Counterclank last week, labeling the software--which is part of such apps as Counter Strike Ground Force, Balloon Game, and Sexy Girls Puzzle--as malware. But rival mobile security firm Lookout published its own analysis of the Counterclank software, also known as the Apperhand software development kit, and came to a different conclusion, instead labeling it as adware.

Notably, Lookout found that although Apperhand was "aggressive" and perhaps demonstrated "bad form"--for example because it can change a smartphone browser's homepage, add arbitrary bookmarks, and place a search icon on the home screen--the software didn't exhibit signs of actually being malicious. Rather, it had all of the classic signs of being part of an adware platform, which some software developers use to earn money from their applications. In the case of Apperhand, that compensation appears to be largely based on driving the users of their apps to specified search engines.

[ Adware recently plagued Google and Facebook sites. Adware Reborn As Facebook Theme Software. ]

Symantec also said that it had alerted Google to the presence of Counterclank in 13 apps sold via the Android Market. But, it said, "Google replied quickly informing us the applications met their terms of service and they will not be removed."

If the "is it adware, or is it malware?" debate sounds familiar, that's because five years ago, controversy raged over how to classify advertising-supported software on Windows PCs. Although its purveyors often labeled their software as adware, security and antivirus companies more often than not labeled it as malware--in part because some so-called adware was actually malicious--and typically blocked both. Some pundits, meanwhile, helpfully just classifed it all as badware.

Likewise, in response to Lookout's analysis of Counterclank, Symantec this week said that regardless of whether the software counts as malware or adware, the bigger question is: Who wants it on their device?

"The situation we find ourselves in is similar to when adware, spyware, and potentially unwanted applications first made appearances on Windows," read a blog post from the Symantec Security Response Team. "Many security vendors did not initially detect these applications, but eventually, and with the universal approval of computer users, security companies chose to notify users of these types of applications."

"Due to the combined behavior of the applications, negative feedback from users who installed the applications, and the fact that previous applications (Android.Tonclank) using this code were initially suspended from the Google Market, we chose to notify users of Counterclank," said Symantec.

Interestingly, Counterclank is a new version of the Tonclank--aka Plankton--software development kit that first began appearing in Android apps this past summer. Although Google initially suspended apps that contained Tonclank, after further review it reinstated them in the Android Market.

Please join us on Feb. 15 for the InformationWeek & Dark Reading virtual event Clouds, Outsourcing, And Security Services: Making Providers Part of Your IT Security Strategy. When you attend, you will be able to access live and on-demand webcast presentations as well as virtual booths packed with free resources, and you can also be eligible to win great prizes! (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5208
Published: 2014-12-22
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers to read arbitrary files via a RETR operation, write to arbit...

CVE-2014-7286
Published: 2014-12-22
Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local users to gain privileges via unspecified vectors.

CVE-2014-8015
Published: 2014-12-22
The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbitrary sponsor's guest account via a modified HTTP request, aka Bug ID CSCur64400.

CVE-2014-8017
Published: 2014-12-22
The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted request that triggers inclusion of a password in a reply, aka Bug ID CSCur41673.

CVE-2014-8018
Published: 2014-12-22
Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application Software in Cisco Unified Communications Domain Manager 8 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCur19651, CSCur18555, CSCur1...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.