Every password, private message, search query, and payment number entered through a keyboard creates valuable information. A keylogger is designed to capture that information by recording what a person types.
Some keystroke-recording tools have legitimate uses, such as authorized troubleshooting, accessibility, or clearly disclosed monitoring on company-owned equipment. A malicious keylogger, however, operates without meaningful permission and sends sensitive information to an attacker.
Because keyloggers usually work silently, the victim may not notice anything unusual until an account is compromised or money disappears.
What Is a Keylogger?
A keylogger, also called a keystroke logger, is software or hardware that records keys pressed on a keyboard or touchscreen.
A malicious keylogger may capture:
- Usernames
- Passwords
- Email messages
- Chat conversations
- Search queries
- Payment-card information
- Banking details
- Identification numbers
- Cryptocurrency recovery phrases
- Confidential business information
- Verification codes
- Information entered into online forms
Modern keyloggers may collect much more than keystrokes. Some can also capture screenshots, clipboard contents, browser activity, window titles, microphone recordings, and stored credentials.
Microsoft describes keyloggers as covert threats that secretly record typing to capture passwords, personal information, and other sensitive data. Microsoft Security
How Does a Keylogger Work?
A software keylogger normally runs in the background and monitors keyboard input.
When the user presses a key, the operating system sends information to the active application. The keylogger intercepts or observes that event and stores it in a log.
The malware may also record contextual information, including:
- Which application was open
- The title of the active window
- The website being visited
- The time each key was pressed
- Screenshots taken during login
- Text copied to the clipboard
The collected data may be stored locally and retrieved later or sent automatically to a remote server.
A hardware keylogger works differently. It records input through a physical device connected to or placed inside the computer.
Common Types of Keyloggers
Software Keylogger
A software keylogger is an application or malicious component installed on the operating system.
It may use ordinary keyboard-monitoring functions, inject code into other processes, or modify system settings to start whenever the device turns on.
Kernel-Level Keylogger
A kernel-level keylogger operates inside the core of the operating system.
Because it runs with powerful privileges, it may observe input before ordinary applications and security tools can process it. Detection and removal can be difficult.
API-Based Keylogger
An API-based keylogger uses normal operating-system interfaces to monitor keyboard activity.
Software may legitimately use some of these interfaces for shortcuts, accessibility, or input management. A malicious program abuses them to record sensitive information.
Form-Grabbing Keylogger
A form grabber captures information submitted through online forms.
Rather than recording every individual key, it may collect the completed username, password, address, or payment details when the user submits the page.
This can be effective even when the website uses HTTPS because the malware captures the information before the browser encrypts it for transmission.
Browser-Based Keylogger
A browser keylogger operates through a malicious extension, injected script, or compromised website.
It may record information entered into login pages, payment forms, webmail, and social-media sites.
Screen Logger
A screen logger takes screenshots when the user performs particular actions.
For example, it may capture images whenever a banking website opens or the mouse clicks near an on-screen keyboard.
Clipboard Logger
A clipboard logger records information that the user copies and pastes.
This can expose passwords, account numbers, wallet addresses, private messages, and other data even when it was never typed manually.
Mobile Keylogger
A mobile keylogger targets smartphones and tablets.
It may abuse accessibility permissions, use a malicious keyboard application, monitor notifications, capture screenshots, or read information displayed in other apps.
Hardware Keylogger
A hardware keylogger is a physical device that records keyboard input.
It may be placed:
- Between a wired keyboard and the computer
- Inside a keyboard
- Inside a USB cable
- Within another connected adapter
- Near a wireless keyboard receiver
Hardware keyloggers do not necessarily appear in the operating system’s application list.
Wireless Keylogger
A wireless keylogger intercepts or monitors signals from a vulnerable wireless keyboard.
Modern encrypted keyboard connections reduce this risk, but outdated or poorly designed equipment may expose input.
Keylogger vs. Spyware
A keylogger is a tool focused on recording input. Spyware is a broader category of software that secretly collects information.
A keylogger can be one feature inside a spyware package. Spyware may also track location, browsing history, messages, photographs, microphone activity, and other information.
Keylogger vs. Trojan Horse
A Trojan horse disguises itself as a legitimate file or program.
A Trojan may install a keylogger after reaching the device. In that situation, “Trojan” describes the delivery method, while “keylogger” describes the surveillance capability.
Keylogger vs. Password Stealer
A keylogger records information as the user types it.
A password stealer searches browsers, applications, cookies, configuration files, and credential stores for information already saved on the device.
One malware program may use both methods.
How Does a Keylogger Get Installed?
Phishing Attachments
A fraudulent email may include an attachment disguised as an invoice, receipt, report, resume, or shared document.
Opening the file can install a keylogger directly or launch a Trojan that downloads it. Microsoft has documented Trojan keyloggers delivered through spear-phishing attachments. Microsoft Security Intelligence
Malicious Downloads
Cracked software, key generators, unofficial VPNs, game modifications, free utilities, and fake security programs may contain hidden monitoring software.
The promised application may function normally while the keylogger runs in the background.
Fake Updates
A website may claim that the browser, operating system, or media software requires an urgent update.
The downloaded file is actually malware.
Malicious Browser Extensions
An extension with permission to read and modify website data may capture information entered into pages.
Extensions should be installed only from trusted developers and removed when no longer needed.
Remote-Access Scams
A technical-support scammer may persuade the victim to install remote-control software.
Once connected, the scammer can install a monitoring tool, change security settings, or steal files.
Software Vulnerabilities
Attackers can exploit an unpatched operating system, browser, driver, or application to install malware without normal authorization.
Physical Access
Someone with access to an unlocked device can install monitoring software or attach a hardware keylogger.
CISA warns that physical access may allow someone to copy information, connect removable devices, or otherwise compromise equipment. CISA
Legitimate and Illegal Uses of Keyloggers
Keylogging technology is not automatically illegal. Authorized uses may include:
- Troubleshooting input problems
- Accessibility functions
- Research and usability testing
- Employee monitoring under applicable policies and laws
- Parental controls used lawfully
- Security testing with permission
Secretly recording another person’s passwords or private communications may violate criminal, privacy, employment, or surveillance laws.
Organizations should use transparent policies, clear authorization, limited data collection, secure storage, and legal review before deploying monitoring technology.
Warning Signs of a Keylogger
A well-designed keylogger may produce no obvious symptoms. Possible warning signs include:
- Keyboard input becoming delayed
- Device slowing unexpectedly
- Unknown background processes
- New startup programs
- Security software being disabled
- Unexplained network activity
- Browser extensions appearing
- Settings changing without permission
- Account-login alerts
- Passwords being compromised repeatedly
- Messages or transactions the user did not authorize
- Clipboard content changing
- Camera or screenshot activity appearing unexpectedly
- Unfamiliar USB adapters attached to the computer
- Security scans detecting spyware or Trojans
These symptoms can have other causes, so they should be investigated rather than treated as proof.
How to Check for a Software Keylogger
Run a Full Security Scan
Update reputable antivirus or anti-malware software and perform a complete scan.
Microsoft recommends trusted security software with real-time protection and behavioral monitoring to detect keyloggers.
Use an Offline Scan
A keylogger with high-level access may hide while the normal operating system is running.
An offline scan starts from a separate trusted environment, reducing the malware’s ability to interfere.
Review Installed Applications
Check for unfamiliar programs, monitoring tools, remote-access applications, and software installed around the time the problem began.
Research unknown names before removing them.
Review Startup Items
Keyloggers often configure themselves to run automatically.
Inspect startup applications, services, scheduled tasks, login items, and background permissions.
Check Browser Extensions
Remove unknown or unnecessary extensions, particularly those with permission to read and change data on every website.
Review Network Connections
Look for unfamiliar applications making repeated outbound connections.
Businesses may use endpoint and network-monitoring tools to identify suspicious communication with remote servers.
How to Check for a Hardware Keylogger
Power down the computer and inspect the keyboard connection.
Look for:
- An unfamiliar adapter between the keyboard and computer
- A replaced or modified USB cable
- Damage to the keyboard casing
- An unknown wireless receiver
- Unexpected equipment behind the computer
- Signs that a shared terminal has been opened
Do not disconnect equipment in a workplace, bank, hotel, library, or other managed location without notifying the owner or security staff. The device may be legitimate, and preserving evidence may be important.
How to Remove a Keylogger
Disconnect the Device
Disconnect the suspected device from the internet and local network.
This may prevent the keylogger from sending additional information.
Stop Entering Sensitive Information
Do not use the device for email, banking, shopping, passwords, private messages, or cryptocurrency.
Use another trusted device for account recovery.
Update Security Software
Install the latest security definitions and perform a full scan.
Microsoft’s security guidance recommends running a complete scan because other hidden malware may accompany a detected keylogger. Microsoft Security Intelligence
Remove Suspicious Applications
Uninstall confirmed malicious programs, browser extensions, and unauthorized remote-access tools.
Restart the device and scan again.
Use an Offline Scanner
Run an offline or recovery-environment scan when the keylogger persists or may have administrator-level access.
Reinstall the Operating System
A clean installation may be the safest response when:
- The keylogger keeps returning
- Administrator access was compromised
- A rootkit may be involved
- Several malware types are present
- Highly sensitive information was entered
Restore only scanned personal files and reinstall applications from official sources.
Remove Hardware Devices
Disconnect a confirmed hardware keylogger after documenting it when appropriate.
Businesses and public organizations should involve security staff or law enforcement before altering possible evidence.
What to Do After Removing a Keylogger
Assume that anything entered while the keylogger was active may have been captured.
From a clean device:
- Change email passwords first
- Change banking and payment passwords
- Replace reused passwords
- Enable multi-factor authentication
- Sign out of all active sessions
- Remove unfamiliar connected apps
- Review recovery email addresses
- Check email forwarding rules
- Contact banks and card issuers
- Monitor account activity
- Replace exposed cryptocurrency wallets
- Notify the employer if business accounts were involved
Microsoft advises changing passwords after the threat has been removed, not while continuing to use the infected device.
How to Prevent Keyloggers
Use Updated Security Software
Enable reputable antivirus or endpoint protection with real-time and behavioral monitoring.
Keep it updated and do not disable it to run an unknown installer.
Install Software Updates
Apply updates to the operating system, browser, applications, drivers, and firmware.
Updates repair vulnerabilities used to install monitoring malware.
Avoid Suspicious Downloads
Download applications only from official stores and verified developer websites.
Avoid cracks, key generators, unofficial VPNs, unknown browser extensions, and fake system optimizers.
Examine Links and Attachments
Do not open unexpected attachments or urgent download links.
Verify unusual messages through another communication method.
Enable Multi-Factor Authentication
MFA can stop some account takeovers even when a password is recorded.
Passkeys and hardware security keys provide stronger phishing-resistant protection for supported accounts. However, no login method makes an infected device safe for sensitive activity.
Use a Password Manager
A password manager reduces the amount of sensitive information typed manually and helps create unique credentials.
Some keyloggers also capture clipboard data, browser sessions, or screenshots, so a password manager should be used as one layer of protection rather than a complete solution.
Secure Physical Access
Lock the screen when leaving a device and restrict access to sensitive workstations.
Inspect shared or public computers before entering private information.
Avoid Sensitive Activity on Public Computers
Do not enter banking, primary email, business administrator, or cryptocurrency credentials on an untrusted public device.
You cannot confirm whether software or hardware monitoring is present.
Review Mobile Keyboard Apps
Use the operating system’s default keyboard or a trusted alternative from the official app store.
A third-party keyboard can potentially access everything typed through it, depending on the platform and permissions.
Limit Administrator Privileges
Use a standard account for ordinary browsing, email, and document work.
Administrator access should be reserved for trusted installations and system changes.
Can a Keylogger Record an On-Screen Keyboard?
Some basic keyloggers record only physical key presses, but advanced malware can capture mouse clicks, screenshots, accessibility data, and form submissions.
An on-screen keyboard is therefore not guaranteed protection on an infected device.
Can a Keylogger See Copied Passwords?
A traditional keylogger may not capture text pasted from the clipboard. However, many modern information-stealing programs include clipboard monitoring.
Assume that both typed and pasted information may be exposed when spyware is present.
Can a Keylogger Work on a Phone?
Yes. Mobile keyloggers may use malicious keyboard applications, accessibility privileges, screenshots, notification access, or system-level exploits.
Review keyboard settings, installed apps, accessibility permissions, administrator profiles, and account activity.
Does Incognito Mode Stop Keyloggers?
No. Incognito or private browsing controls what the browser stores locally after a session.
It does not prevent malware on the device from recording keystrokes, screenshots, clipboard data, or network activity.
Will a Factory Reset Remove a Keylogger?
A factory reset or clean operating-system installation removes most software keyloggers.
It will not remove a physical hardware keylogger, and the infection can return through an unsafe backup, compromised account, or reinstalled malicious application.
