FBI runs Trojan horse

Fed's email virus reads key strokes to bypass encryption

James Middleton

The FBI may be in possession of software capable of remotely compromising a suspect's computer and installing a keylogger to harvest encryption key passwords.

The discovery comes only weeks after the Bureau made a motion to suppress evidence about the use of similar technology in the recent US versus Nicodemo Scarfo case. The FBI claimed that releasing information about the technology would jeopardise current as well as future investigations.

Advertisement

A report on the so-called 'Magic Lantern' software by MSNBC reveals that the tool operates much like a Trojan horse. It arrives in an email and then installs itself invisibly and sets up a keylogger which presumably captures such data as the pass code for an encryption program such as PGP and forwards it to the FBI.

The tool has a lot in common with Dirt, the phantom program developed by Codex Data Systems, which claims to fit remote monitoring capabilities in a 20Kb package and place a Trojan in any other type of file.

It is thought that authorities are turning to such drastic measures because criminals using encryption systems always seem to have the upper hand as in the Scarfo case.

Only last month the FBI's Carnivore project won a major victory with the passing of the USA Patriot Act, which means that agents only need to obtain permission from a state attorney general to use spy tapping techniques. Previously they would require an order from a judge.

However, the tech community has met the news with as much derision as it did Dirt, and it has struck a nerve on the Slashdot forum.

"Does this mean it will now be illegal to use a secure system? Having any type of security/virus protection will be a circumvention of law-enforcing software," said one user.

Others slammed the software on its scant technical detail, claiming that Linux users would be immune because of the different nature in which *nix email clients work.

"This only works if: a) The FBI kicks in your door and installs Outlook; b) You always open email with the subject 'Snow White and the 7 FBI Agents'; c) You run the attachment called 'FBILOVESYOU.VBS'," came one humorous retort.

Another issue is the fact that antivirus software would technically prevent Magic Lantern from being executed. Similarly, the developers of Dirt admitted that the only reason antivirus software didn't detect their tool was because the antivirus companies had not got hold of a copy to develop a virus signature for it.

Magic Lantern is the latest in a series of tools being developed for the FBI's DragonWare suite which features Carnivore, Packeteer and Coolminer.

Magic Lantern and its sibling tools, whatever they are, go under the project name 'Cyber Knight' which is designed to match captured data with relevant encryption keys and thus speed up the investigation process.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

FBI Trojan goes underground

Malicious copy of Magic Lantern on the prowl

FBI in firing line over 'good' Trojan

No such thing, say AV vendors

Remote access Trojans on the warpath

The future of viruses is more of the same

FBI wants to keep technology secret

Mobster case could render FBI's keystroke program useless

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

a padlock

Microsoft to plug security holes

Microsoft has given advance warning of a number of security...

Nokia handset

Top 10 articles, 10 July 09

No Nokia Android phone, ActiveX attacks and Google enters into...

Can Google beat Microsoft at its own game?

Google's announcement this week that it plans to step into...

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Primary Navigation