Over the weekend, the “Chaos Computer Club” (CCC), a group considered to be the largest European Hacker Club, said it had identified and reverse engineered a Windows backdoor trojan that the group claims is being used by the German government.
The group provided a 20-page document (PDF, in German) detailing its analysis of the “lawful interception” malware program they say can “siphon away intimate data” and has backdoor functionality that allows it to execute other arbitrary programs.
“The government malware can, unchecked by a judge, load extensions by remote control, to use the trojan for other functions, including but not limited to eavesdropping,” the group wrote in a note on Saturday when announcing its discovery. “This complete control over the infected PC – owing to the poor craftsmanship that went into this trojan – is open not just to the agency that put it there, but to everyone.”
“The backdoor includes a keylogger that targets certain applications including Firefox, Skype, MSN Messenger, ICQ and others,” according to Mikko Hypponen, Chief Research Officer at F-Secure. “The backdoor also contains code intended to take screenshots and record audio, including recording Skype calls. In addition, the backdoor can be remotely updated. Servers that it connects to include 83.236.140.90 and 207.158.22.134,” he added.
While the malware is rather complex, the CCC criticized the developers for their sloppy security built into the software. “We were surprised and shocked by the lack of even elementary security in the code. Any attacker could assume control of a computer infiltrated by the German law enforcement authorities.” While many elements may point to as coming from a German Government agency, it’s too early to make an official accusation right now.
“We have no reason to suspect CCC’s findings, but we can’t confirm that this trojan was written by the German government,” Hypponen, commented in a blog post. “As far as we see, the only party that could confirm that would be the German government itself.”
F-Secure, along with Sophos, have each pledged to detect the backdoor. We expect several other vendors to follow with announcements on the malware over the next couple days.

For more than 10 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.
More from Mike Lennon
- ‘No Evidence’ of Cyberattack Related to FAA Outage, White House Says
- SecurityWeek to Host 2022 ICS Cybersecurity Conference October 24-27 in Atlanta
- Google Completes $5.4 Billion Acquisition of Mandiant
- Cybersecurity Firm ZeroFox Begins Trading on Nasdaq via SPAC Deal
- HUMAN Security and PerimeterX Merge on Mission to Combat Bots
- Last Call: CFP for ICS Cybersecurity Conference Closes July 15th
- Johnson Controls Acquires Tempered Networks to Shield Buildings From Cyberattacks
- Snowflake Launches Cybersecurity Workload to Find Threats Across Massive Data Sets
Latest News
- Malicious NPM, PyPI Packages Stealing User Information
- VMware Confirms Exploit Code Released for Critical vRealize Logging Vulnerabilities
- 98% of Firms Have a Supply Chain Relationship That Has Been Breached: Analysis
- Dutch, European Hospitals ‘Hit by Pro-Russian Hackers’
- Gem Security Gets $11 Million Seed Investment for Cloud Incident Response Platform
- Ransomware Leads to Nantucket Public Schools Shutdown
- Stop, Collaborate and Listen: Disrupting Cybercrime Networks Requires Private-Public Cooperation and Information Sharing
- Boxx Insurance Raises $14.4 Million in Series B Funding
