Keylogger
A type of spyware that records every keystroke a user types, capturing passwords, messages, and other sensitive input.
Definition
A keylogger is a type of spyware, delivered as either software or a physical device, that records every keystroke made on a keyboard and sends the captured data to an attacker. It is commonly used to steal login credentials, credit card numbers, and confidential messages as they are typed, before any encryption is applied.
Software keyloggers are usually installed through a phishing attachment, a bundled malicious download, or as part of a broader malware infection, running invisibly in the background of an infected device. Hardware keyloggers are physical devices, sometimes disguised as a USB adapter, connected between a keyboard and a computer, which is a particular risk in shared or public workspaces. In both forms, everything typed, including usernames, passwords, and one-time codes entered manually, is captured before it can be protected by encryption on screen.
Keyloggers are especially dangerous because they defeat many standard defenses: even a strong, unique password offers no protection if it is captured the moment it is typed. This makes keyloggers a common precursor to account takeover and business email compromise, since a captured password combined with a captured one-time code can bypass some multi-factor authentication methods. Shared computers in bank branches, cyber cafes, and public kiosks common in Indonesia are attractive targets for hardware keyloggers because many people use the same device.
Reputable anti-malware software can detect and remove most software keyloggers, and regularly inspecting physical keyboard connections helps catch hardware devices in shared environments. Using a password manager with autofill reduces exposure because credentials are entered without manual typing, and phishing-resistant multi-factor authentication such as passkeys removes the value of a captured password entirely. Employees should also be cautious about typing sensitive credentials on shared or public computers whenever an alternative is available.
At a glance
- Severity
- High
- Prevalence
- Common, particularly on shared computers
- Primary targets
- Anyone entering credentials on an infected device, or shared and public computers
How it works
- 1
Installation: software keyloggers arrive through a phishing attachment, bundled download, or broader malware infection, running invisibly in the background.
- 2
Physical variant: hardware keyloggers are physical devices, sometimes disguised as a USB adapter, connected between a keyboard and computer.
- 3
Capture: every keystroke, including usernames, passwords, and manually entered one-time codes, is recorded.
- 4
Transmission: the captured data is sent to the attacker before it can be protected by on-screen encryption.
- 5
Exploitation: captured credentials are used directly for account takeover or business email compromise.
Warning signs
- An unfamiliar USB adapter or device connected between a keyboard and computer
- Slower typing response or unusual keyboard behavior on a device
- Unexplained account logins shortly after typing credentials on a shared computer
- Antivirus alerts flagging unfamiliar background processes
- A one-time code or password that stops working immediately after being typed once
How to defend
- Use reputable anti-malware software that can detect and remove software keyloggers
- Regularly inspect physical keyboard connections in shared workspaces
- Use a password manager with autofill so credentials are entered without manual typing
- Adopt phishing-resistant multi-factor authentication such as passkeys, which removes the value of a captured password
- Avoid typing sensitive credentials on shared or public computers when an alternative is available
Real-world example
A customer at an internet cafe in a small Indonesian city types their online banking password on a shared computer with a hidden hardware keylogger attached. Days later, the attacker retrieves the device, extracts the captured keystrokes, and logs into the customer's account to drain their savings.
How Claro helps
Claro's security awareness content explains how keyloggers undermine password-based defenses, reinforcing why password managers and stronger authentication methods matter in daily habits.
Frequently asked questions
What is the difference between a keylogger and spyware?
A keylogger is a specific type of spyware that focuses only on recording keystrokes. Spyware is the broader category that can also capture screenshots, browsing activity, and camera or microphone access.
Can a strong password protect against a keylogger?
No. A keylogger captures the password the moment it is typed, regardless of how strong or unique it is, which is why password managers with autofill and phishing-resistant MFA are more effective defenses.
How do hardware keyloggers get installed?
They are physical devices plugged in between a keyboard and a computer, often in shared or public spaces, and can be disguised to look like a normal USB adapter.
Does multi-factor authentication stop keyloggers?
Phishing-resistant methods like passkeys do, since there is no password or one-time code left to capture. Weaker methods, such as manually typed one-time codes, can still be captured alongside the password.
Related terms
Malware
Any software intentionally designed to damage, disrupt, or gain unauthorized access to a device or network.
Spyware
Software that secretly monitors a user's activity and collects information such as browsing habits, keystrokes, or credentials without consent.
Credential Harvesting
Credential harvesting is the theft of usernames, passwords, and other login data, usually through fake login pages or deceptive messages, so attackers can access accounts and systems.
Account Takeover
When an attacker gains unauthorized control of a user's online account, typically through stolen credentials, and uses it for fraud or further attacks.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo