Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

Chinese Antivirus Firm NQ Called 'Massive Fraud'

Mobile anti-malware software developer NQ Mobile denies charges that it inflates its market share and makes spyware.

9 Android Apps To Improve Security, Privacy
9 Android Apps To Improve Security, Privacy
(click image for larger view)
Is Chinese mobile security software vendor NQ Mobile "a massive fraud"?

That allegation was leveled in a report from research firm Muddy Waters, released Thursday, which labeled as "fictitious" 72% of the security company's reported 2012 income.

"Our research estimates that NQ's real market share in China is only about 1.5%, versus the approximately 55% it reports," the report said. "We estimate that its China paying user base is less than 250,000, versus the 6 million NQ claims."

Adding fuel to the fire, the Los Angeles-based research firm said "top-flight security software engineers" that it hired to review NQ Mobile's antivirus software reported that it posed an information security and privacy risk to users. "NQ's Antivirus 7.0 is unsafe for sale to consumers, and we consider it to be spyware that makes users' phones vulnerable to cyber attack," it said. "Phones are vulnerable to MITM [man-in-the-middle] attacks because NQ fails to adhere to basic security protocols."

[ Would you let LinkedIn scan your emails? Read LinkedIn Intro Service Triggers Security, Privacy Fears. ]

But NQ Mobile, which has dual headquarters in Beijing and China, strongly dismissed the allegations. "The company believes that the allegations and accusations set forth in the Muddy Waters report are false and inaccurate and contain numerous errors of facts, misleading speculations and malicious interpretations of events," said a statement the company released Friday. It included what the company said was a list of 14 major term deposits in cash, which it referenced "as confirmation of the strong foundations of our business."

NQ Mobile recently enjoyed a meteoric rise in its stock market fortunes, gaining 280% in value and trading alongside Netflix and Tesla, Forbes reported. But after the release of the Muddy Waters report, the company's stock market value plunged $500 million Thursday, and trading on the stock was halted several times that day.

Investors, in other words, appear to be heeding allegations contained in the Muddy Waters report, which labeled NQ's management team as being "sloppy, to the point of being comical, fraudsters." It also said that the company's cash balances haven't been verified by an auditor, concluding that "NQ's cash balances are highly likely to not exist."

The report added: "The one intelligent move NQ made to further its fraud is putting in place the veneer of U.S. management -- particularly 'Co-CEO' Omar Khan. Were Mr. Khan not fronting for NQ, we do not think that investors would have been so willing to overlook so many red flags."

According to the report, Khan, who isn't part of the Chinese entity of NQ Mobile's board of directors or management team, received a compensation package worth almost $100 million from NQ Mobile, "which is likely far more than he would have earned as a non-C level manager at Citigroup."

Muddy Waters is run by China-based expatriate Carson Block, who's made a career of short-selling companies -- often Chinese firms listed in U.S. exchanges -- for which he's accused of fraudulently inflating assets, revenue, market share or other key indicators of success. Short-selling refers to making stock market bets against companies, using borrowed shares, meaning that if Block criticizes a firm and the value of its shares tank, he stands to make a significant profit.

Block first made his name in 2011, when he accused Chinese forestry firm Sino-Forest of massaging its assets and revenue, triggering a $4 billion lawsuit again him. Block labeled the lawsuit as being "without merit." Sino-Forest ultimately filed for bankruptcy.

According to Bloomberg, Block singlehandedly erased $7 billion from Chinese companies' stock-market valuation between 2010 and 2012.

This isn't the first time that market watchers have accused NQ Mobile of massaging its market share. In December 2012, market researcher FJE Research questioned NQ Mobile's statement that it controlled 63% of China's mobile security market, saying that it believed rival Qihoo controlled at least 60%. It also said that download levels of NQ Mobile's security application via Chinese community site Sina and various app stores suggested the firm's market share was substantially lower.

In response, NQ Mobile released a statement saying that it "strongly rejects these allegations" and noted that the research firm "has admitted to holding a short position in the company." NQ Mobile added that it only acquired about 20% of its new users from app stores. "The rest are from working with a number of mobile ad networks to provide users with direct download from the company's server," it said. The company also said that about 20% of its new users came via mobile device manufacturers -- including Coolpad, Gionee, Hisense, Huawei, Motorola, Nokia, Samsung and ZTE -- who preinstalled its software on their mobile devices, and accused its critics of ignoring these channels.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
SOC 2s & Third-Party Assessments: How to Prevent Them from Being Used in a Data Breach Lawsuit
Beth Burgin Waller, Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLC,  12/5/2019
Navigating Security in the Cloud
Diya Jolly, Chief Product Officer, Okta,  12/4/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19604
PUBLISHED: 2019-12-11
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.
CVE-2019-14861
PUBLISHED: 2019-12-10
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permiss...
CVE-2019-14870
PUBLISHED: 2019-12-10
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authent...
CVE-2019-14889
PUBLISHED: 2019-12-10
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence...
CVE-2019-1484
PUBLISHED: 2019-12-10
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.