Risk
2/1/2012
12:01 PM
50%
50%

Counterclank Apps To Remain In Android Market

Some security experts call Counterclank apps malware, not adware. But Google says the apps comply with the company's terms of service.

10 Great Android Collaboration Apps
10 Great Android Collaboration Apps
(click image for larger view and for slideshow)
Google said a controversial set of advertising-supported Android apps will remain in its official Android Market, because they comply with the company's terms of service. The 13 apps in question, which Google said have been collectively downloaded up to 5 million times, use adware software known as Counterclank.

Symantec first sounded the alarm over Counterclank last week, labeling the software--which is part of such apps as Counter Strike Ground Force, Balloon Game, and Sexy Girls Puzzle--as malware. But rival mobile security firm Lookout published its own analysis of the Counterclank software, also known as the Apperhand software development kit, and came to a different conclusion, instead labeling it as adware.

Notably, Lookout found that although Apperhand was "aggressive" and perhaps demonstrated "bad form"--for example because it can change a smartphone browser's homepage, add arbitrary bookmarks, and place a search icon on the home screen--the software didn't exhibit signs of actually being malicious. Rather, it had all of the classic signs of being part of an adware platform, which some software developers use to earn money from their applications. In the case of Apperhand, that compensation appears to be largely based on driving the users of their apps to specified search engines.

[ Adware recently plagued Google and Facebook sites. Adware Reborn As Facebook Theme Software. ]

Symantec also said that it had alerted Google to the presence of Counterclank in 13 apps sold via the Android Market. But, it said, "Google replied quickly informing us the applications met their terms of service and they will not be removed."

If the "is it adware, or is it malware?" debate sounds familiar, that's because five years ago, controversy raged over how to classify advertising-supported software on Windows PCs. Although its purveyors often labeled their software as adware, security and antivirus companies more often than not labeled it as malware--in part because some so-called adware was actually malicious--and typically blocked both. Some pundits, meanwhile, helpfully just classifed it all as badware.

Likewise, in response to Lookout's analysis of Counterclank, Symantec this week said that regardless of whether the software counts as malware or adware, the bigger question is: Who wants it on their device?

"The situation we find ourselves in is similar to when adware, spyware, and potentially unwanted applications first made appearances on Windows," read a blog post from the Symantec Security Response Team. "Many security vendors did not initially detect these applications, but eventually, and with the universal approval of computer users, security companies chose to notify users of these types of applications."

"Due to the combined behavior of the applications, negative feedback from users who installed the applications, and the fact that previous applications (Android.Tonclank) using this code were initially suspended from the Google Market, we chose to notify users of Counterclank," said Symantec.

Interestingly, Counterclank is a new version of the Tonclank--aka Plankton--software development kit that first began appearing in Android apps this past summer. Although Google initially suspended apps that contained Tonclank, after further review it reinstated them in the Android Market.

Please join us on Feb. 15 for the InformationWeek & Dark Reading virtual event Clouds, Outsourcing, And Security Services: Making Providers Part of Your IT Security Strategy. When you attend, you will be able to access live and on-demand webcast presentations as well as virtual booths packed with free resources, and you can also be eligible to win great prizes! (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Five Things Every Business Executive Should Know About Cybersecurity
Don't get lost in security's technical minutiae - a clearer picture of what's at stake can help align business imperatives with technology execution.
Flash Poll
Dark Reading Strategic Security Report: The Impact of Enterprise Data Breaches
Dark Reading Strategic Security Report: The Impact of Enterprise Data Breaches
Social engineering, ransomware, and other sophisticated exploits are leading to new IT security compromises every day. Dark Reading's 2016 Strategic Security Survey polled 300 IT and security professionals to get information on breach incidents, the fallout they caused, and how recent events are shaping preparations for inevitable attacks in the coming year. Download this report to get a look at data from the survey and to find out what a breach might mean for your organization.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Security researchers are finding that there's a growing market for the vulnerabilities they discover and persistent conundrum as to the right way to disclose them. Dark Reading editors will speak to experts -- Veracode CTO and co-founder Chris Wysopal and HackerOne co-founder and CTO Alex Rice -- about bug bounties and the expanding market for zero-day security vulnerabilities.