“KeySweeper is a stealthy Ardunio-based device camouflaged as a wall charger that wirelessly sniffs, decrypts, logs and reports-back all keystrokes from any Microsoft wireless keyboard in the vicinity,” Kamkar said.
The security researcher has also released instructions on how to build the USB wall charger online and surprisinglyits is cheap to build and quite capable. KeySweeper includes a web-based tool for live keystroke monitoring, capable to send SMS alerts for typed keystrokes, usernames, or URLs, and even continues to work after it is unplugged because of its rechargeable built-in battery.
“Even if we do not know the MAC address, we can decrypt the keystroke. Using a few-dollar Arduino and a US$1 Nordic RF chip we can decrypt these packets and see any keystroke of any keyboard in the vicinity that’s using the Microsoft wireless keyboard protocol and it doesn’t matter what OS is used.“
Keysweeper stores the captured keystrokes both online and locally, and then send it back to the KeySweeper operator over the Internet via an optional GSM chip.
- $3 – $30: An Arduino or Teensy microcontroller can be used.
- $1: nRF24L01+ 2.4GHz RF Chip which communicates using GFSK over 2.4GHz.
- $6: AC USB Charger for converting AC power to 5v DC.
- $2 (Optional): An optional SPI Serial Flash chip can be used to store keystrokes on.
- $45 (Optional): Adafruit has created a board called the FONA which allows you to use a 2G SIM card to send/receive SMS, phone calls, and use the Internet directly from the device.
- $3 (Optional if using FONA): The FONA requires a mini-SIM card (not a micro-SIM).
- $5 (Optional, only if using FONA): The FONA provides on-board LiPo/LiOn battery recharging, and while KeySweeper is connected to AC power, the battery will be kept charged, but is required nonetheless.