Nodea — logo

Keylogger

A keylogger (keystroke logger) is a type of spyware or a hardware device whose job is to secretly record everything a user types on the keyboard. The captured keystrokes — logins, passwords, payment card numbers, message contents — are then sent to an attacker. Keyloggers are among the most dangerous identity-theft tools because they run in the background and stay unnoticed for a long time.

How a keylogger works

Depending on its form, there are two main types:

  • software keyloggers — applications installed on a system, usually without the user's knowledge, that intercept keyboard events at the operating-system, browser or kernel level; they often spread as part of trojans, adware or attachments in phishing campaigns;
  • hardware keyloggers — physical devices plugged in between the keyboard and the computer or mounted inside the hardware; antivirus software can't detect them, but they require physical access to the machine.

Advanced variants record not just keystrokes but also screenshots, clipboard contents and visited pages, building a complete picture of the victim's activity.

Practical application

In criminal hands, keyloggers are used to hijack bank accounts, email, site admin panels and social-media profiles. They are especially dangerous for administrators and anyone managing infrastructure, because captured credentials for a server or hosting panel open the door to further attacks such as ransomware.

Protection relies on several layers: up-to-date antivirus and anti-malware, current system patches, caution with attachments and links, using a password manager (which fills fields automatically, bypassing keyboard entry) and — crucially — two-factor authentication, which neutralises a stolen password string on its own. It's worth noting that keyloggers can also be legitimate — as parental-control or workplace-monitoring tools used with the user's consent.

Powiązane pojęcia

Najczęstsze pytania

How can I tell if my computer has a keylogger?

Hardware keyloggers may appear as a small adapter between the keyboard and a USB port. Software ones are harder to spot — they may cause system slowdowns, unusual network activity or unfamiliar processes. An up-to-date antivirus and anti-malware scan is the most reliable way to detect them.

Does two-factor authentication protect against keyloggers?

It significantly limits the damage. Even if a keylogger captures your password, without the second factor (an app code or a hardware key) an attacker can't log in. That's why 2FA is one of the most effective defences when login credentials alone are leaked.