Researcher Michael Myng found a deactivated keylogger in a piece of software found on over 460 HP laptop models. A full list of affected laptops is here. The keylogger is deactivated by default but could represent a privacy concern if an attacker has physical access to the computer.
“Some time ago someone asked me if I can figure out how to control HP’s laptop keyboard backlight,” wrote Myng. “I asked for the keyboard driver SynTP.sys, opened it in IDA, and after some browsing noticed a few interesting strings.”
The strings led to something that appeared to be a hidden keylogger – a program that sends typed characters to an attacker – in a Synaptics device driver. Given that the decompiled code prepared and sent key presses to an unnamed target, Myng was fairly certain he had something interesting on his hands.
Luckily, HP responded quickly.
Latest posts by Peter Kivuti (see all)
- Banking Trojan Trickbot New Tricks - January 10, 2019
- Internet-facing endpoints are exposing businesses worldwide to a botnet which is now being used in targeted ransomware campaigns: Phorpiex worm - January 10, 2019
- How safe is your data?: Two-pronged cyber attack infects victims with data-stealing trojan malware and ransomware - January 9, 2019