Samsung Accused of Installing Keyloggers on Laptops

Security consultant Mohamed Hassan made a shocking discovery when he bought a Samsung laptop last month: Pre-installed software was recording his every keystroke.

Writing for NetworkWorld, Hassan says he discovered the key-logging software, called Starlogger, on a Samsung R525 laptop after running a full system scan with commercial security software, and before installing anything else on the computer. Starlogger captures all text entry, including passwords and emails, and can even take screenshots. The software then discretely transmits its findings by e-mail.

It gets worse. After removing Starlogger, Hassan returned the laptop due to an unrelated issue with the video driver. He then purchased another Samsung laptop, model R540, from a different retailer. Sure enough, he found the same Starlogger software in the same directory (c:\windows\SL) on a different Samsung computer.

“The fact that on both models the same files were found in the same location supported the suspicion that the hardware manufacturer, Samsung, must know about this software on its brand-new laptops,” Hassan wrote.

NetworkWorld contacted three Samsung public relations reps, giving them a week to comment before running the story. None responded. But when Hassan called Samsung support, a supervisor confirmed that Samsung installed the software to “monitor the performance of the machine and to find out how it is being used.”

Hassan likens this incident to the Sony BMG rootkit fiasco of 2005, in which music CDs came pre-loaded with monitoring software to prevent piracy. “This is a déjà vu security incident with far reaching potential consequences,” he wrote.

If Hassan’s allegations are accurate, Samsung could face lawsuits, and may be liable if the information it reportedly collected fell into the wrong hands.

Either way, Samsung’s got some serious explaining to do.

UPDATE: False alarm. Please see the updated story here.

Related Topics: computer security, Computers, Gadgets, Samsung
  • pks29733steel

    Just another reminder not to waste my money on ‘Samsung’ products!!

  • cyberprivateer

    Wow, talk about losing market momentum! These guys have a serious PR problem, now. Which should signal the Chinese (called “the usual suspects” in cyber adventures like hacking the Australians) how fast they’d better turn their own image. Chinese cell phones and computers are automatically suspect.

  • http://www.alexlogic.com alexlogic

    This idea that computers are strictly for consumption needs to be stopped. Some people CREATE on their computer, and these people certainly don’t need their intellectual property sent out via email.

  • http://conceptvbs.wordpress.com conceptvbs

    Go try this… create a windows\sl directory then run spyware doctor or vipre… run a scan.. they will report you are infected with the same keylogger… they are simply triggering on the existance of an “sl” directory and the author of original post didn’t do ANY research on this.. he just assumed Spyware Dr. was correct and then wrote about it. lame.

blog comments powered by Disqus