Spyware is designed to watch quietly. Unlike ransomware, which announces an attack by locking files, spyware often tries to remain invisible for as long as possible. It can monitor browsing activity, collect passwords, record keystrokes, track a phone’s location, or send private information to someone else without the owner’s informed permission.
Some spyware arrives through malicious downloads and fraudulent links. Other programs are installed by someone with physical access to the device. Even applications that appear useful can contain hidden tracking features or collect far more information than a user expects.
Because spyware works in the background, recognizing its warning signs is an important part of protecting your privacy, accounts, and financial information.
What Is Spyware?
Spyware is software that secretly collects information from a computer, smartphone, tablet, or other connected device.
Depending on its capabilities, spyware may collect:
- Usernames and passwords
- Banking and card information
- Browsing history
- Search activity
- Email and private messages
- Photographs and files
- Device location
- Microphone recordings
- Camera access
- Contact lists
- Clipboard contents
- Login verification codes
The collected information may be sent to cybercriminals, advertisers, abusive individuals, or other unauthorized parties.
Spyware belongs to the broader category of malware, but not every form of data collection is technically spyware. Legitimate applications also gather information for analytics, advertising, and personalization. The difference usually involves transparency, consent, purpose, and the user’s ability to control the collection.
How Does Spyware Work?
Spyware normally enters a device by hiding inside another file, application, browser extension, or installation process.
After installation, it attempts to operate without attracting attention. It may start automatically whenever the device turns on, disguise itself under an ordinary-looking name, or obtain powerful permissions that allow it to access private information.
More advanced spyware can:
- Record activity on the device
- Store the collected information temporarily
- Connect to a remote server
- Send the information to its operator
- Receive new instructions
- Update or reinstall itself
Some spyware focuses on a single task, such as displaying unwanted advertisements. Other programs provide broad surveillance capabilities and can monitor nearly everything a person does on the device.
Common Types of Spyware
Keyloggers
A keylogger records keys typed on a keyboard. This can reveal passwords, private messages, search queries, card numbers, and other information.
Software-based keyloggers run on the device, while physical keyloggers may be connected between a keyboard and computer. Some legitimate monitoring and accessibility tools also include keystroke-recording functions, but secretly using them to collect private information is dangerous and may be illegal.
Password Stealers
Password-stealing malware searches browsers, email applications, password databases, cookies, and other stored information for account credentials.
It may also steal active login sessions. This can allow a criminal to enter an account without manually typing the victim’s password.
Banking Spyware
Banking spyware targets online banking, payment applications, cryptocurrency services, and shopping accounts.
It may record login information, replace payment details, capture verification codes, or display a fake form over a legitimate banking application.
Adware
Adware displays unwanted advertisements and may monitor browsing behavior to deliver targeted promotions.
Not all advertising-supported software is malicious. However, adware becomes a serious concern when it installs without clear permission, changes browser settings, tracks users excessively, or directs them to dangerous websites.
Browser Hijackers
A browser hijacker changes browser settings without permission. It may replace the homepage, alter the default search engine, add unwanted toolbars, or redirect searches to advertising and scam websites.
Browser hijackers can also monitor browsing activity and collect information about the pages a user visits.
System Monitors
System-monitoring spyware can capture screenshots, record applications, track file activity, monitor messages, and create detailed reports about device usage.
Businesses may use clearly disclosed monitoring software on company-owned devices. Secret installation on someone’s personal device is different and can create serious privacy and safety concerns.
Mobile Spyware
Mobile spyware is designed for smartphones and tablets. It may collect messages, photographs, contacts, location data, call records, and information from other applications.
Some versions can activate a microphone, track real-time movement, or abuse accessibility permissions to read what appears on the screen.
Stalkerware
Stalkerware is monitoring software used to secretly track another person, often by a current or former intimate partner.
It may reveal location, calls, messages, browsing history, and social-media activity. The person installing it usually needs physical access to the device, although compromised cloud accounts can also expose private information.
Removing stalkerware can sometimes alert the person responsible. If you believe an abusive person is monitoring you, prioritize your physical safety and seek help from a trusted device. The FTC’s stalkerware guidance recommends considering safety before changing or removing anything.
Commercial Spyware
Commercial spyware is sold as a surveillance or intelligence product. Highly advanced versions may exploit previously unknown security weaknesses and target journalists, political figures, activists, lawyers, government officials, and other high-risk individuals.
These tools are different from ordinary consumer malware because they can be expensive, targeted, and difficult to detect.
How Does Spyware Get Installed?
Bundled Software
Spyware may be included with free software, download managers, browser tools, game modifications, cracked programs, or unofficial media applications.
The unwanted component may be hidden inside a rushed installation process or described using vague language that most people do not read.
Phishing Links and Attachments
A fraudulent email or text message may direct the recipient to a malicious website or attachment.
The file may look like an invoice, photograph, security update, document, or delivery notice. Opening it can install spyware directly or create access for another attacker.
Fake Software Updates
A website may display a warning claiming that the browser, media player, antivirus software, or operating system requires an urgent update.
The downloaded “update” is actually malicious software.
Unofficial Application Stores
Applications from unofficial stores and third-party download sites may not receive the same level of review as apps distributed through established platforms.
In 2025, the UK’s National Cyber Security Centre warned about spyware hidden inside mobile apps promoted to particular communities and recommended downloading applications only from official app stores. NCSC
Malicious Browser Extensions
A browser extension may request permission to read every website visited, modify page content, access browsing history, or manage downloads.
An extension with excessive permissions can collect valuable information or insert advertisements into web pages.
Physical Access to the Device
A person who knows the device passcode may install monitoring software, change account settings, add a fingerprint, or connect the device to another account.
Spyware installed through physical access is especially relevant in cases involving stalkerware and domestic abuse.
Security Vulnerabilities
Advanced attackers may exploit a weakness in the operating system or application. In rare cases, a so-called zero-click attack may compromise a device without requiring the user to open a link.
Regular updates reduce exposure to known vulnerabilities, although no device can be guaranteed completely immune from advanced attacks.
Warning Signs of Spyware
Spyware is designed to stay hidden, and many symptoms can also be caused by normal software problems. One sign alone does not prove that a device is infected.
Possible warning signs include:
- Battery draining much faster than usual
- Device becoming hot while it is not being used
- Unexplained increases in mobile-data usage
- Apps opening, closing, or crashing unexpectedly
- New applications the owner does not recognize
- Browser homepage or search engine changing
- Frequent pop-ups and unwanted advertisements
- Microphone or camera indicators appearing unexpectedly
- Strange sounds during phone calls
- Unexplained account-login alerts
- Security settings changing without permission
- Device performance becoming unusually slow
- Messages marked as read before the owner opens them
- Location services remaining active without an obvious reason
- An abusive person knowing private details they should not know
Modern phones provide privacy dashboards showing which applications recently accessed the camera, microphone, location, contacts, and other information. Reviewing this activity can reveal an application using permissions at unexpected times.
How to Check a Computer for Spyware
Review Installed Applications
Open the device’s application list and look for programs you do not recognize. Research suspicious names using another trusted device when possible.
Do not immediately delete unfamiliar system components, because removing essential software can cause additional problems.
Inspect Browser Extensions
Review every installed extension and remove anything unnecessary, unfamiliar, or downloaded from an untrusted source.
Also check the homepage, default search engine, site-notification permissions, and proxy settings.
Run a Security Scan
Update reputable antivirus or anti-malware software and perform a complete scan.
The FTC recommends keeping security software updated and configuring it to scan new files automatically. FTC Consumer Advice
Check Startup Programs
Spyware often configures itself to run whenever the device starts. Review startup applications and background processes for unfamiliar entries.
Advanced system changes should be examined by a qualified technician rather than removed at random.
Review Network Activity
Unexpected network traffic can indicate that an application is sending information elsewhere. Operating-system tools and reputable security products may show which programs are using the network.
How to Check a Phone for Spyware
Review Application Permissions
Check which apps can access:
- Location
- Camera
- Microphone
- Contacts
- Messages
- Call logs
- Photos
- Accessibility services
- Device administration
Remove permissions that an application does not need.
Look for Unknown Accounts and Profiles
Review connected email accounts, device-management profiles, VPN settings, and administrator applications.
An unknown management profile can give another party substantial control over the device.
Check Location Sharing
Review location-sharing settings in the operating system, maps applications, family accounts, social media, and messaging services.
A person may be tracking location through a shared account rather than spyware installed directly on the phone.
Check Account Security
Review active sessions, trusted devices, recovery addresses, and recent login activity for major accounts.
Change compromised passwords from a safe device and enable multi-factor authentication.
How to Remove Spyware
Disconnect From the Internet
If you suspect an active infection, disconnect the device from Wi-Fi, Ethernet, and mobile data. This may temporarily prevent the spyware from sending additional information.
Stop Entering Sensitive Information
Avoid banking, shopping, email login, or password changes on the suspected device until it has been checked.
Use a different trusted device for important account-security actions.
Update Security Software and Scan
Update your security software, run a full scan, and quarantine or remove confirmed threats.
Restart the device and scan again to check whether the spyware returns.
Remove Suspicious Applications
Uninstall confirmed malicious applications and browser extensions. Revoke their permissions and remove any associated device-management profiles.
If an application cannot be removed, a security tool or professional technician may be required.
Change Passwords Safely
From a clean device, change passwords for email, banking, cloud storage, social media, and other important accounts.
Use unique credentials and enable two-factor authentication. Review account-recovery options in case the attacker changed them.
Reinstall the Operating System
A clean operating-system installation or factory reset can remove many spyware infections.
Back up only essential documents, photographs, and other personal files. Avoid restoring unknown applications or a complete backup that may contain the spyware.
The FTC notes that reinstalling apps from an infected phone backup could restore stalkerware, so applications should be downloaded again from the official store when possible.
Seek Specialist Help
Highly targeted individuals, businesses handling sensitive information, and people facing domestic abuse may require expert assistance.
Use a safe device when contacting a cybersecurity professional, law-enforcement agency, lawyer, employer, or support organization.
How to Prevent Spyware
Download Software From Trusted Sources
Use official app stores and developers’ genuine websites. Avoid cracked software, unofficial installers, key generators, and unknown browser extensions.
Check the publisher’s identity, reviews, download history, and requested permissions before installing anything.
Install Updates Promptly
Keep the operating system, browser, applications, router, and security software updated.
Updates often repair security weaknesses that spyware can exploit.
Use Security Software
Enable reputable security protection and automatic scanning. Keep built-in operating-system protections active unless a trusted alternative replaces them.
Be Careful With Pop-Ups
Do not click buttons inside unexpected warning windows. A fake pop-up may use both “Allow” and “Cancel” buttons to trigger the same malicious action.
Close the browser tab or application through the operating system when necessary. CISA similarly advises users not to click links inside suspicious pop-up windows. CISA
Review Permissions Regularly
An application may request more access after an update or when a new feature is enabled.
Periodically review camera, microphone, location, accessibility, and contact permissions. Remove access that is no longer necessary.
Lock Devices Securely
Protect phones, tablets, and computers with a strong passcode, password, or biometric lock.
Do not share the passcode with people who do not need it. Configure the device to lock automatically after a short period of inactivity.
Enable Multi-Factor Authentication
Multi-factor authentication can help protect an account when spyware captures a password.
A passkey or hardware security key can provide stronger protection than verification codes in some situations.
Avoid Administrator Accounts for Daily Use
Use a standard account for ordinary computer activity. Administrator access should be reserved for trusted software installations and system changes.
This can limit what some unwanted applications are able to do.
Check Privacy and Security Settings
Review account sessions, connected applications, email forwarding rules, location sharing, browser notifications, and cloud backups.
Removing forgotten connections reduces the number of ways someone can continue collecting information.
Is Spyware the Same as a Virus?
No. A computer virus is defined by its ability to attach itself to files and spread when those files run. Spyware is defined by its purpose: secretly monitoring activity or collecting information.
A program can have characteristics of both spyware and a virus, but the terms do not mean exactly the same thing.
Can Spyware See Everything on a Phone?
That depends on the spyware’s permissions and technical capabilities. Basic spyware may only collect advertising or browsing information. More powerful mobile spyware can potentially access messages, location, recordings, photographs, contacts, and login information.
Modern operating systems restrict application access, but spyware may abuse accessibility features, administrator privileges, security vulnerabilities, or compromised cloud accounts to gain broader visibility.
Can Spyware Use a Camera or Microphone?
Spyware with the required permissions—or the ability to bypass those protections—may activate a device’s camera or microphone.
Review privacy indicators and permission history. Unexpected camera or microphone activity should be investigated, particularly if it happens while no relevant application is being used.
Will a Factory Reset Remove Spyware?
A proper factory reset removes many common spyware applications. It may not solve the problem if the attacker still controls an email or cloud account, the device is enrolled in unauthorized management, or an infected backup restores the software.
After resetting, install current system updates, change important passwords from a trusted device, enable multi-factor authentication, and download applications individually from official sources.
