I believe the complaint here is not that they were analyzing the software, but that they were launching active attacks and using the results in an unethical manner, i.e. to conduct possibly-illegal criminal investigations. This is Not OK in the same way that it's Not OK to go around breaking into people's houses with lockpicks and searching them on the grounds that you are conducting lock research. Note that I understand that physical lock security is a relatively well-settled field. That is not relevant to the point at hand; even if it were an important thing to study, it would be Not OK for the government to be paying people to go around picking locks.
Edit: Furthermore, by the same logic, it is acceptable for the government to do nearly anything illegal in order to conduct "research". Microsoft, Google, and co claim to be secure, so therefore it should be OK for the government to be attacking them.
Edit: Furthermore, by the same logic, it is acceptable for the government to do nearly anything illegal in order to conduct "research". Microsoft, Google, and co claim to be secure, so therefore it should be OK for the government to be attacking them.