Skip to main content

Mechanical keyboard maker accused of keylogging as customers examine software

keylogging
Image used with permission by copyright holder
Jump on Amazon to perform a search for mechanical keyboards and the cheapest solutions you find are sold by manufacturers you likely don’t know. MantisTek is one of these lesser-known keyboard makers and is now under fire for allegedly tracking the typed keys of those who own its GK2 mechanical keyboard, aka keylogging. This alleged tracking is done through the included software, which sends information to a server maintained by the Alibaba Group.

Typically, the software can be used to customize the keyboard’s RGB illumination, lighting effects, and macro assignments. But a few owners are reporting that the software sends data to an IP address owned by Alibaba. A post stemming out of Asia provides a few more detailed bits, reporting that MantisTek’s “cloud driver” is the responsible component sending data to a specific address: 47.90.52.88.

If you enter that address in a browser, a Chinese login page appears along with a link to Browse Happy. The page translates to “Cloud mouse platform background management system,” and is maintained by Shenzhen Cytec Technology Co., Ltd., which may or may not be a rechargeable battery maker located in Shenzhen, China (Cytec doesn’t appear in a web search, but Cytac does).

According to the report, the keyboard’s software sends keypress statistics to two destinations at that IP address: “/cms/json/putkeyusedata.php” and “/cms/json/putuserevent.php.” An analysis shows that all information is crossing the internet in plain text, meaning its unencrypted and exposed to anyone snooping on your internet connection. That means hackers — in addition to MantisTek — can grab anything you type, including email addresses, bank account numbers, and login credentials.

The best defense against MantisTek’s alleged keystroke snooping is to not use the GK2’s included software. Based on the product information, you can adjust the illumination and lighting effects manually on the keyboard using a combination of keys. You can do the same when recording macros.

But if you wish for the software to remain installed, then block CMS.exe in your firewall to prevent the software from sending and receiving information over the internet. To do this in Windows 10, type “Windows Firewall” into Cortana’s search field on the taskbar, click on “Windows Defender Firewall with Advanced Security.” After that, add a new Inbound and Outbound rule for CMS.exe.

Mechanical keyboards with virtually no security issues (that we know of) are typically manufactured by high-profile companies such as Razer, Corsair, Logitech, Roccat, Microsoft, Cooler Master, Thermaltake, and a few others. But even with these products, installing software should only be necessary if you want access to the keyboard’s core features. The less software you install, the happier your PC will be.

To be clear, Alibaba isn’t collecting information from owners of the MantisTek GK2 mechanical keyboard. The company provides cloud services, aka Alibaba Cloud, including an elastic compute service, a virtual private cloud, an analytic database, and anti-DDOS services. The “cloud driver” may be silently collecting information for analytic purposes rather than intentionally collecting sensitive information

Still, keylogging is unacceptable no matter the root intention.

Editors' Recommendations

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
How to draw on Google Docs to add doodles, sketches, and more
The Google Play Store, YouTube, and Google Docs installed on an Amazon Fire Max 11.

Word processing software isn’t the kind of tool that most users would consider exciting, which is why we’re glad to see companies like Google adding a little flair to its own products. We’re talking about Google Docs, a free-to-use word processor that’s part of your larger Google Account ecosystem. Basic formatting options and other familiar word processing functions are front and center on Google Docs, but the ability to add doodles, sketches, and other entertaining media to your next Docs file requires a special bit of know-how.

Read more
AMD’s upcoming APUs might destroy your GPU
AMD CEO Lisa Su holding an APU chip.

The spec sheets for AMD's upcoming APU lineups, dubbed Strix Point and Strix Halo, have just been leaked, and it's safe to say that they're looking pretty impressive. Equipped with Zen 5 cores, the new APUs will find their way to laptops that are meant to be on the thinner side, but their performance might rival that of some of the best budget graphics cards -- and that's without having a discrete GPU.

While AMD hasn't unveiled Strix Point (STX) and Strix Halo (STX Halo) specs just yet, they were leaked by HKEPC and then shared by VideoCardz. The sheet goes over the maximum specs for each APU lineup, the first of which, Strix Point, is rumored to launch this year. Strix Halo, said to be significantly more powerful, is currently slated for a 2025 release.

Read more
Hyte made me fall in love with my gaming PC all over again
A PC built with the Hyte Nexus Link ecosystem.

I've never seen anything quite like Hyte's new Nexus Link ecosystem. Corsair has its iCue Link system, and Lian Li has its magnetic Uni system, and all three companies are now offering ways to tie together your PC cooling and lighting devoid of extraneous cables. But Hyte's marriage of hardware, software, and accessories is in a league of its own -- and it transformed my PC build completely.

I've been using some of the foundational components of the ecosystem for about a week, retailoring a build inside of Hyte's own Y40 PC case to see how the system works. It doesn't seem too exciting at first -- Hyte released an all-in-one (AIO) liquid cooler, some fans, and a few RGB strips, who cares? But as I engaged more with the Nexus Link ecosystem, I only became more impressed.
It all starts with the cooler

Read more