The Federal Trade Commission has clamped down on a company that sells a keylogger. On Wednesday, the agency announced a settlement with CyberSpy Software barring it from advertising that its RemoteSpy keylogger can be disguised and installed on someone’s computer without the user’s knowledge.
The settlement, which resulted in a court order by the U.S. District Court for the Middle District of Florida, also requires that the program give notice to the user that the software has been downloaded, and the user must agree to installation. It also prohibits the company from disguising the program as a harmless attachment. The final settlement was accepted unanimously by the FTC, 5-0.
‘Spy on Anyone’
In addition, the agency said, the settlement requires the Orlando, Fla.-based company to “take measures to reduce the risk that their spyware is misused, encrypt data transmitted over the Internet, police their affiliates to ensure they comply with the order, and remove legacy versions of the software from computers” on which the program is already installed.
The FTC originally sued CyberSpy and its owner, Tracer R. Spence, in 2008 for advertising and selling RemoteSpy. CyberSpy’s ads had bragged that it was “100 percent undetectable” and that purchasers could “Spy on Anyone. From Anywhere.”
The agency said in court papers that the company provided step-by-step instructions on how to make the software look like it was a harmless file, such as a photo, and then attach it to an e-mail. When the attachment was downloaded, the RemoteSpy program installed without the user’s knowledge.
Once installed, the keylogger records every keystroke, such as passwords, captures images, and keeps track of web sites visited by the user. The program then reports this information back to a web site run by CyberSpy, where clients could log on to retrieve the private data.
‘Computer Monitoring Software’
On its web site,…