Back to glossary

Keylogger

3 min read

A keylogger is hardware or software that records the keys pressed on a device, covertly and without the user’s knowledge, in order to capture passwords and anything else typed.

July 30, 2026
Compartir:

A keylogger is a tool, in hardware or in software, built to record and track the keystrokes made on a device such as a computer or a phone, covertly and without the user knowing.

It gets used for surveillance, for stealing confidential information, and for monitoring people who have not agreed to be monitored.

From a security point of view a keylogger is a serious threat, because what it captures is exactly the material an attacker wants: passwords, card numbers and personal information, all typed in plain text by the person who owns them.

How they work

Keyloggers record keystrokes in two broad ways: through hardware, or through software.

Hardware keyloggers. A physical device connected between the keyboard and the computer, recording everything typed. They are less common than the software kind and can be harder to find, because they need no access to the operating system at all and no software on the machine will ever see them.

Software keyloggers. Programs installed covertly on the target system, either with physical access or through social engineering: a phishing email, a malicious download. Once installed they record keystrokes and send what they capture to a server the attacker controls.

Software keyloggers come in several variants:

Kernel based. They operate at the operating system kernel level, which lets them record everything from the keyboard before the data reaches any application.

API based. They use the operating system’s programming interfaces to intercept and record keystrokes.

Form grabbing. They target specific information entered into web forms, usernames and passwords in particular, capturing it before it is submitted to the server.

What actually limits the damage

Because a keylogger captures what is typed, the controls that help most are the ones that make a typed secret insufficient on its own.

A password manager that fills credentials rather than having the user type them removes a great deal of what a keylogger would otherwise get. A second factor means the captured password is not enough. Passkeys remove the typed secret entirely.

None of that prevents the infection, and all of it reduces what the infection is worth, which is usually the more achievable goal.

A worked example

An employee downloads and installs a free third party utility on their work computer, without realising it carries a keylogger.

As they use the machine to reach business systems and type confidential passwords, the keylogger records the keystrokes and sends them to a server the attacker controls.

The attacker now has the employee’s login credentials, and from there the corporate network.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.