Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

09:49 PM

Jury Still Out On Mobile Adware

Malicious software or not? Defining the threat on mobile platforms becomes more difficult as some advertising software enters a gray area

On Friday, security firm Symantec warned that a baker's dozen of applications available through the Android Marketplace hosted a "bot-like threat" that could leak information.

With an estimated 1 million to 5 million installations, the threat -- dubbed Counterclank by Symantec -- would have been one of the largest outbreaks of mobile malware to date. Yet other security firms disagreed over the details: The affected programs incorporated third-party software that was not malicious but comprised "an aggressive form of ad network," concluded mobile security firm Lookout.

The incident highlights that uncertain gray areas continue to inhabit the space between what is definitely a legitimate mobile application and what is purely malicious.

"I think we are in a place where people are being very experimental, and people are coming up with new ideas for a new platform," says Tim Wyatt, a principal engineer at Lookout. "We will definitely see ideas that push the boundaries of what is acceptable and what is not."

The debate follows a similar trajectory as the concerns over spyware, adware, and unwanted programs that plagued PC users at the beginning of last decade. In the early 2000s, the infamous affiliate adware maker 180Solutions, later known as Zango, paid partners to install its software on systems, which they often did without the users' permission.

In a similar way, some mobile advertising platforms perform functions that users would likely not want, if they had a choice. Counterclank, which is actually the Apperhand software development kit, collects the international mobile equipment identifier (IMEI) and uses the push notification mechanism to send personalized ads to the user's device. Software using the development kit also leaves a search icon on a mobile device's desktop and can modify bookmarks.

The last capability is unacceptable behavior but not malicious, Lookout states in its analysis.

Other companies agree. Counterclank may not be malware, but its definitely unwanted, says Roel Schouwenberg, senior researcher with security firm Kaspersky. The company classifies the program, not as malicious, but as something that users would not want on their mobile device. Whether that determination stays constant is an open question, he says.

"It is definitely grayware," Schouwenberg says. "We haven't quite hashed out yet whether [programs using it] are malicious or not. We are currently detecting it, but I would not be surprised if somewhere down the line, we decide not to detect it or detect it in a different way."

On the Android platform, many security firms focus on the types and number of permissions requested by programs as an initial indicator that something may be amiss. However, permissions by themselves are not sufficient, says Schouwenberg.

"We see quite a lot of apps out there that ask for a ton of permissions," he says. "Developers are copy-pasting the permissions list off of a template, and going with it, when in reality, they will never use some of those permissions."

Yet, permissions that seem excessive -- such as GPS tracking, connecting to an Internet server and the ability to read data from the phone -- are actually necessary, argues some developers. Full-function advertising platforms need to assign a user a unique ID and offer other benefits to their clients, argues mobile advertising software maker Mobclix.

"GPS activation, Internet connectivity and read phone state, when accessed, are not signs you’ve accidentally put malware into your application," the company writes in a blog post. "They’re usually legitimately accessed – along with other data and functions we rarely think about."

As mobile application development -- and the business models that drive it -- matures, the gray area will shrink, says Schouwenberg. In addition, customer concerns will likely drive developers to focus on reducing the expansive permission sets that are currently the norm.

"Quick growth and security generally don't go hand in hand," he says. "When the rapid growth starts winding down a bit, that's when Google [and developers] will look and see what they can improve on."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
NSA Appoints Rob Joyce as Cyber Director
Dark Reading Staff 1/15/2021
Vulnerability Management Has a Data Problem
Tal Morgenstern, Co-Founder & Chief Product Officer, Vulcan Cyber,  1/14/2021
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This is not what I meant by "I would like to share some desk space"
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-01-21
Possible memory out of bound issue during music playback when an incorrect bit stream content is copied into array without checking the length of array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobi...
PUBLISHED: 2021-01-21
Local privilege escalation in admin services in Windows environment can occur due to an arbitrary read issue in XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
PUBLISHED: 2021-01-21
Possible out of bound memory access in audio due to integer underflow while processing modified contents in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon We...
PUBLISHED: 2021-01-21
Memory corruption while calculating L2CAP packet length in reassembly logic when remote sends more data than expected in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Weara...
PUBLISHED: 2021-01-21
Arbitrary read and write to kernel addresses by temporarily overwriting ring buffer pointer and creating a race condition. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon ...