Tuesday, April 15, 2025
HomeHacksDangerous Keylogger Found in MantisTek GK2 Keyboard that Capture Users Data and...

Dangerous Keylogger Found in MantisTek GK2 Keyboard that Capture Users Data and Sending into China

Published on

SIEM as a Service

Follow Us on Google News

A very popular Gaming Keyboard MantisTek GK2 104 Keys has found with a keylogger that records all the user keyboard activities and sends it across to Cloud Server which is belongs to China.

This mid-range mechanical keyboard cost around US$ 49.99 that is selling via many e-commerce websites in online.

This Keyboard designed to record the keypress Activites of the users that will send the captured Details to a remote server.

- Advertisement - Google News

Further investigation revealed that captured data has sent to the Alibaba cloud server. Alibaba sells cloud services, so the data isn’t necessarily being sent to Alibaba, the company, but to someone else using an Alibaba server.

Also Read:  KRACK Detector – Tool to Detect and Prevent From KRACK Attacks on Your Network

Majority of gadgets that come from China contains very low quality with lacking of privacy and security issue that sometimes causes to collecting users data without consumers Knowledge.

One of Reddit online user has been Experienced that, apparently the software of the Mantistek GK2 is sending all our keypress to an Alibaba.com server! This is sick, imagine the level of information they have about passwords and logins.

In this Image Captured by one of MantisTek Keyboard users clearly showing that keylogger sending user data into which is placed in China.

According to Tomshardware,  to The main issue seems to be caused by the keyboard’s “Cloud Driver,” which sends information to IP addresses tied to Alibaba servers. The data being sent—in plaintext, no less— has been identified as a count on how many times keys have been pressed.

“The first way to stop the keyboard from sending your key presses to the Alibaba server is to ensure the MantisTek Cloud Driver software isn’t running in the background.”

The second method to stop the data collection is to block the CMS.exe executable in your firewall. You could do this by adding a new firewall rule for the MantisTek Cloud Driver in the “Windows Defender Firewall With Advanced Security. Tomshardware said.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Over 100,000 WordPress Plugin VUlnerability Exploited Just 4 Hours After Disclosure

Over 100,000 WordPress websites have been exposed to a critical security vulnerability, following the...

Hackers Use Microsoft Teams Chats to Deliver Malware to Windows PCs

A sophisticated cyberattack campaign has emerged, leveraging Microsoft Teams chats to infiltrate Windows PCs...

Apache Roller Vulnerability Allows Hackers to Bypass Access Controls

A newly disclosed vulnerability in Apache Roller, the popular open-source blog server, could allow...

Galaxy S24 Vulnerability Poses Risk of Unauthorized File Access

A security flaw in Samsung’s Quick Share feature for the Galaxy S24 series has...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Researchers Uncover Hacking Tools and Techniques Shared on Russian-Speaking Cybercrime Forums

Trend Micro, a cybersecurity firm, has released its 50th installment report on the Russian-speaking...

Kellogg’s Servers Breached, Hackers Steal Sensitive Data

WK Kellogg Co., one of the world's leading cereal and snack manufacturers, has fallen...

20-Year-Old Scattered Spider Hacker Pleads Guilty in Major Ransomware Case

A 20-year-old Noah Urban, a resident of Palm Coast, Florida, pleaded guilty to a...