Skip the navigation
)
News

Symantec recants Android malware claims

Now agrees with rival that apps use aggressive ad network code, declines to label them 'adware'

February 1, 2012 03:48 PM ET

Computerworld - Symantec has backtracked from assertions last week that 13 Android apps distributed by Google's Android Market were malicious, and now says that the code in question comes from an aggressive ad network that provides revenue to the smartphone programs.

The security firm's new stance was in line with that taken by Lookout Security, which on Friday questioned Symantec's conclusions and instead said that the apps displayed the same behavior as others funded by 10 or more similar ad networks.

Symantec dubbed the code embedded within the 13 apps "Android.Counterclank," and classified it as a Trojan horse, or malware. According to Symantec's researchers, the malware was a variation on "Android.TonClank," called "Plankton" by researchers at North Carolina State University, another Trojan first uncovered in June 2011.

The apps containing the Android.Counterclank code had been downloaded between 1 million and 5 million times, said Symantec, which used the Android Market's own published numbers to arrive at that range. That made it the "largest malware [outbreak] on the Android Market," Kevin Haley, a director with Symantec's security response team, said in an interview last Friday.

In a blog post Monday, Symantec retracted its earlier allegations and said that the Android.Counterclank code comes from an SDK, or software development kit, distributed to "third parties to help them monetize their applications, primarily through search."

Symantec declined to name the ad network that distributes the SDK responsible for the code it detects as Android.Counterclank.

Both Symantec and Lookout have noted that the ad network code used by the 13 apps is more aggressive than the norm.

"In general, it's changing the home page of the [smartphone's] browser, adding additional shortcuts to the desktop, adding and even removing bookmarks," said Haley in a follow-up interview today.

So, if the Android.Counterclank apps are not malicious, what are they? Adware, the name pinned to unwanted PC software in the last decade?

Haley wasn't ready or willing to assign a label.

"It took a while for some consensus then about what was adware or spyware, and what wasn't," said Haley, talking about the intense debate five-to-seven years ago about those terms. "But eventually that consensus was reached."

Symantec will still identify apps that include Android.Counterclank -- a name it's also continuing to use -- but will not delete them, said Haley.

"We will come up with labels when it's appropriate," said Halley. "Now, we will make sure that we tell customers what's going on on their phones. We'll tell them what it does, and let them make the decision whether they want to make the trade-off and keep the app."

That was essentially the same practices that security companies used initially during the debates over adware and spyware on Windows PCs. Eventually, most antivirus vendors moved to a more forceful approach, and started to automatically remove such software.

"This is an inevitable discussion on mobile," said Haley. "We're going to see app vendors experiment with how to monetize their apps on Android phones, more so on mobile than on the PC, because mobile apps are sold at very inexpensive prices or given away for free. It's understandable that we'll see some pushing the boundaries, or even going beyond them."

Symantec said it reported the 13 apps with the Android.Counterclank code to Google, but that Google said the apps did not violate any of its policies, and would remain in the Android Market.

"We expect in the future there may be many similar situations where we will inform users about an application, but the application will remain in the Google Android Market," Symantec noted.

Google has declined to comment on Symantec's original malware claims or on the counter-arguments made by Lookout Security.

covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at Twitter @gkeizer, on Google+ or subscribe to Gregg's RSS feed Keizer RSS. His e-mail address is gkeizer@computerworld.com.

See .

Read more about Mobile Apps and Services in Computerworld's Mobile Apps and Services Topic Center.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Mobile Apps and Services White Papers
Mobile Middleware Strategies
Learn why a mobile development platform is critical to be able to support today's complex enterprise mobility strategies. Learn what to look for...
The Evolution of Enterprise Mobile App Development
Driven by explosive growth in smartphone and tablet sales, enterprise mobility has become an essential part of business. Organizations across industries are developing...
Native & HTML5 Mobile Apps: Not an either or, but a where and when
Learn how developers are using HTML5 and native development methods to build mobile apps. Get practical insights on how these tools are being...
Bank Improves Crisis Management Communications with Help from BlackBerry Solution
With a staff of more than 60,000 people dispersed across the United States, U.S. Bank needed a robust and intuitive program that would...
Why Centralized Cloud Identity Management is Crucial for the Enterprise
Now that employees are leaving the relative safety of the firewall to use online SaaS applications, enterprises need to adjust the way they...
All Mobile Apps and Services White Papers
Mobile Apps and Services Webcasts
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Apps that add business value
BlackBerry® has all that you need to leverage mobile applications for BlackBerry® smartphones and BlackBerry® PlayBook™ tablets. You will see some simple applications...
Distributed Database Security with Real-time Monitoring
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
InfoSphere Warehouse Packs Demo
These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
All Mobile Apps and Services Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs