AUTO-UPDATED

Open-source stealth USB hides an encrypted partition behind an 8GB decoy drive — 'Phantom Drive' appears as a regular USB stick until you create a text file to unlock the hidden data

Rootkit Labs has released the Phantomdrive, an open-source, inconspicuous USB device that uses AES-256 encryption and a hidden partition to protect sensitive data from unauthorized physical access.

Key Points

  • The Phantomdrive utilizes a CH569 microcontroller and a user-provided microSD card to manage both a decoy 8GB partition and a hidden, encrypted storage area.
  • Firmware intercepts specific text file commands to unlock the hidden partition, ensuring the password is never written to the physical storage cells.
  • Security features include PBKDF2-HMAC-SHA-256 hashing with intentional delays to prevent brute-force attacks and hardware-bound encryption keys.
  • Users can spoof vendor IDs to make the device appear as a standard, low-cost USB drive from brands like Kingston to avoid suspicion.
  • The project is fully open-source, with schematics, PCB layouts, and firmware available on GitHub, or available for purchase from Rootkit Labs for $50.

Why it Matters

This device provides a low-cost, DIY-friendly solution for individuals operating in environments where digital privacy and encryption rights are actively threatened. By prioritizing physical obfuscation and hardware-level security, it offers a practical tool for protecting sensitive information against forced disclosure or unauthorized inspection.
Tom's Hardware UK Published by editors@tomshardware.com (Hassam Nasir) , Hassam Nasir
Read original