Microsoft Wireless Keyboards Allegedly Susceptible to Keylogger Disguised as USB Charger

Advertisement
By NDTV Correspondent | Updated: 16 January 2015 15:38 IST

Security researcher Samy Kamkar, well known for his prolific and creative work in exposing vulnerabilities on the Web and in various electronic products, has released details of a keylogger that can sniff keystrokes transmitted from several models of Microsoft wireless keyboards. The device is so tiny that it can be hidden inside common products. Kamkar has shown off a working device hidden inside a USB charger and, thus completely disguising it.

As noted by Ars Technica, the device, called KeySweeper, sounds like something right out of a spy movie. It works because Microsoft uses weak security to encrypt the proprietary connection between the wireless keyboards and their receivers. Making matters worse, each keyboard's wireless MAC address, which can easily be skipped, is used as the encryption key.

Advertisement

The hardware required is a tiny Arduino or Teensy board with a Nordic Semiconductor nRF24L01+ radio frequency transceiver. The design is customisable enough to allow for a battery, SIM card and integrated flash storage. Using these components, the KeySweeper could be hidden inside any ordinary-looking product and work even if it was lying on a table or in a drawer near the intended victim. An entire device can be assembled for less than $10 (approximately Rs. 620).

Kamkar has published details including schematics and source code on his website. He also warns anyone trying to replicate the device that it is potentially dangerous to modify chargers, which plug directly into AC outlets. The device can just as easily receive power from any other source.

Advertisement

KeySweeper could either store keystrokes locally or transmit them via cellular networks. Going beyond this, the device could even send SMS messages to grab an attacker's attention when specific keywords such as usernames, web addresses, etc are typed.

Kamkar claims he purchased a brand new Microsoft wireless keyboard from a retail chain in order to demonstrate the vulnerability. Microsoft, however, has issued a statement to Ars Technica which claims that only devices sold prior to July 2011 are affected, since the company started using better AES encryption at that time. Wireless keyboards using Blueooth rather than proprietary RF are not susceptible to KeySweeper.

Advertisement


The vulnerability in Microsoft's keyboards has been known for a while, but it was previously believed that much larger and more powerful equipment would be needed in order to sniff keystrokes. Those who regularly type sensitive information would of course be even more secure with an ordinary wired keyboard.

Advertisement

Kamkar is perhaps best known as the author of the Samy worm, which, in 2005, became known for being the first to exploit Web 2.0 cross-site scripting vulnerabilities and propagate itself. The Samy worm caused MySpace to go down for several days. Kamkar is a regular speaker at security conferences and has worked to identify weaknesses in RFID and wireless payments systems, expose persistent user tracking,circumvent Internet censorship, and shield users from governments that snoop on communications. In 2011, he published data proving that Apple, Microsoft and Google had been tracking smartphone users' locations en masse. Most recently, he developed a way to hijack unmanned drones and force them to accept his own commands.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Motorola Edge 70 Pro+ With 6,500mAh Battery Debuts in India at This Price
  2. Xiaomi 17T Launches in India With Leica-Tuned Triple Rear Cameras
  3. Infinix Smart 20 to Launch in India Next Week With These Features
  4. Xiaomi TV FX Mini LED Series With Up to 75-Inch Screen Launched in India
  5. Xiaomi 17T vs Vivo X200T vs Samsung Galaxy A57: Price, Features Compared
  6. Motorola Edge 70 Pro+ vs Vivo V70 vs Nothing Phone 4a Pro Compared
  1. Nintendo Switch 2 Could Get a Removable Battery Variant Next Year to Comply With EU Regulations
  2. FIFA World Cup 2026: LASD Issues Warning Over Crypto Scams Days Ahead of World Cup
  3. Dridam OTT Release Date: When and Where to Watch Shane Nigam’s Crime Thriller Online
  4. Gram Chikitsalay Season 2 OTT Release Date: When and Where to Watch it Online?
  5. Samsung Reportedly Developing Carbon Standing Case for Galaxy Z Fold 8, Galaxy Z Fold 8 Ultra
  6. Vi Unveils Silent Mobile Verification for ‘Faster’ Verification on WhatsApp, Instagram and Facebook in India
  7. Amazon Expands Visual Search With AI-Generated Product Previews, Lens Live and Circle to Search Features
  8. US DoJ Targets Scam Networks in Southeast Asia, Freezes $3 Million in Joint Operation Involving Coinbase, Meta, Microsoft and Starlink
  9. Sony WH-1000XM6 Now Available in India in New Sandstone Finish: Price, Features
  10. Infinix Smart 20 India Launch Date Confirmed as Microsite Reveals Key Specifications, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.