Mastodon Mastodon Mastodon Mastodon

Keylogger

Updated: · CyberSecureFox Editorial Team

A keylogger is a program or hardware device that records keystrokes on a computer or phone, allowing an attacker to capture passwords, messages and card numbers as they are typed.

How a keylogger works

  • Software keyloggers hook into the operating system’s keyboard input, the browser or individual apps. Many also take screenshots, record the clipboard and grab form data before it is encrypted and sent.
  • Hardware keyloggers are small adapters between the keyboard and the computer, or modified keyboards and cables; they need physical access.
  • Mobile keyloggers on Android often abuse accessibility services or install a malicious on-screen keyboard.

Keylogging is rarely a standalone tool today. It is a module of infostealers, banking trojans, remote access trojans and spyware. Agent Tesla and Snake Keylogger are widely spread examples, usually delivered through phishing emails with fake invoices.

Why keyloggers matter for security

A keylogger defeats even long and complex passwords because it records them at the moment of entry. Stolen logins give access to email, corporate systems, banking and crypto exchanges. Keyloggers are also used for insider monitoring and stalking, which raises legal and privacy issues – monitoring someone’s device without consent is illegal in many countries.

How to protect yourself

  • Enable two-factor authentication, preferably with passkeys or hardware keys, so that a captured password alone is useless.
  • Use a password manager with autofill – it reduces typing of passwords.
  • Keep security software updated and avoid running unknown attachments.
  • On shared or public computers, do not enter sensitive credentials; check for unknown adapters on the keyboard cable.
Synonyms:
keystroke logger