This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Symantec reveals large scale Android malware threat

by Chris Martin

30 Jan 2012

View Comments

  • Tweet this
Android Market logo

Millions of Android users may have unwittingly installed a Trojan known as Android.Counterclank, making it the most widely distributed piece of malware on Google's smartphone operating system.

A group of three publishers have distributed Android.Counterclank within apps on the Android Market. It is a version of the older Android.Tonclank and has been found in 13 apps which have a combined millions of times.

"The combined download figures of all the malicious apps indicate that Android.Counterclank has the highest distribution of any malware identified so far this year." said Symantec in a blog post.

Symantec explained that the malicious code has been put into the apps inside a packet named "Apperhand" and that a compromised device can have data stolen or be made to carry out certain tasks without permission.

At the time of writing only five of the apps are still on the Android Market place, including Sexy Girls Photo Game and Deal & Be Millionaire. The latter has had between one million and five million installs in the past 30 days.

The Millionaire app page also reveals some strange permissions on installation, including access to the phones features which can determine the phone number and serial number of the phone.

One user reported seeing suspicious activity on their phone after installing the app, giving an insight into how it affects a device.

"It requests the ability to add/remove icons to your home screen! Upon running the game for the first time it adds a suspicious 'Search' icon to your home screen," they said.

Symantec confirmed the search icon as a sign of infection.

But Lookout, a firm which specialises in mobile security, had a different take on the situation, as it explained in a blog post.

"We disagree with the assessment that this is malware, although we do believe that the Apperhand SDK [software development kit] is an aggressive form of ad network and should be taken seriously," it said.

Symantec said it is still investigating the issue and will post further information as it becomes available.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

16%

55%

10%

10%

9%

Popular Threads

Powered by Disqus
BlackBerry Q5

BlackBerry Q5 video demo

BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

Oracle Applications Database Administrator - Oracle EBS DBA

Oracle Applications Database Administrator - Oracle Apps...

BMC BPPM / Patrol Automation Tools Administrator

BMC Tools Administrator - Patrol, BPPM, Remedy, Remedy...

C++ Developer - iPhone iOS Objective-C

C++ Developer / C++ Software Engineer (Mobile iPhone...

.Net Developer, ASP.Net, C#, MVC - Manchester, Warrington

.Net Developer, ASP.Net, MVC, C# - Manchester, Greater...

To send to more than one email address, simply separate each address with a comma.