Google won't kill 'malicious' Android apps

Powered by SC Magazine
 

Apps dubbed malicious by Symantec did not violate terms of service.

Google will not remove 13 Android applications dubbed malcious by security firm Symantec.

The applications included action, adventure and puzzle games that had data stealing capabilities, according to Symantec.

The security company said the apps included the software development kit (SDK) dubbed Appherhand that installed a search bar on the user's phone and allowed the distributors to change the user's home page and add and remove bookmarks and shortcuts.

Symantec security response director Kevin Haley said questioned the legitimacy of Apperhand.

"I'm not sure why you would need to pull someone's bookmarks," Haley told SCMagazine.com."I'm not aware of the benefit."

The apps contained a trojan dubbed by Symantec as Counterclank and have been downloaded between one and five million times, Haley said.

Apperhand was similar to an SDK  present in other apps that appeared recently in the Android Market.

They carried malicious code dubbed Plankton which provided distributors with remote access to a users' device.

Google temporarily suspended the apps but later found they were not harmful.

"You should be aware what you're getting into when you download these apps, and if you don't want them taking these actions on your phone, then I think you should remove them," Haley said.

Google would not remove the apps stating they did not violate its terms of service, Symantec said.

Lookout Mobile Security said it does not consider the applications malware but "an aggressive form of [an] ad network" which "should be taken seriously".

As the mobile device space continues to mature, security companies and platform providers will be forced to sort out applications worth flagging.

Haley likened this to the early days of the PC industry when spyware programs routinely were considered innocuous.

"Maybe we don't have all the nomenclature set yet in the Android or malware space."

"We're building consensus on what these things ought to be called."

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


Google won't kill 'malicious' Android apps
Flickr
 
 
 
Top Stories
At the top of her game
A decision to bring digital operations back in-house three years ago has paid big dividends for Tabcorp.
 
Westpac hires SAP man as CTO
Creates four new IT lead positions.
 
Qld Transport to replace core registration system
State's biggest citizen info repository set for overhaul.
 
 
Flickr
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
More 4G from Optus in Darwin
Nov 21, 2014
Click to see where Optus has expanded coverage to the suburbs near Darwin.
Optus steps up regional 4G coverage
Nov 20, 2014
Once 700Mhz services are working, Optus claims regional users will have a "faster and more ...
This Huawei 4G phone costs $99
Nov 12, 2014
The $99 Huawei Ascend Y550, available through Vodafone, enters the budget market as one of the ...
4G smartphones: Microsoft's Lumia 830
Nov 7, 2014
Microsoft has announced its flagship Windows Phone, the Nokia Lumia 830 4G, will be available in ...
Do you direct debit customers? Read this
Oct 10, 2014
Authorities have been targeting direct debit practices with iiNet and Dodo receiving formal ...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  38%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  21%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 979

Vote