Skip to Content

Keylogger: capturing every keystroke without the user's knowledge

A keylogger (keystroke logger) discreetly captures everything a victim types on their keyboard, credentials, passwords, messages, and sends this information to an attacker, often with no visible sign of its presence.

Definition

A keylogger may be purely software-based, installed via a malware, or hardware-based, in the form of a small device connected between the keyboard and the computer. Its stealth is its main strength: a victim may use it for weeks without suspecting anything.

It is often one component among others in a broader attack, allowing an attacker to retrieve credentials that will then be used for unauthorized access or an account theft. Up-to-date antivirus software and an EDR significantly reduce this risk.

Key points

Discreet, continuous capture

Every keystroke is recorded and transmitted, with no visible action for the user.

Software or hardware

A keylogger may be installed malware, or a small physical device connected to the keyboard.

A springboard for other attacks

Captured credentials often serve as the starting point for account theft or unauthorized access.

How BCIT can support you

Multi-factor authentication greatly limits the impact of credentials captured by a keylogger: see our page MFA. An up-to-date EDR also detects most software keyloggers before they capture sensitive information.

Frequently asked questions ❓

Can a keylogger be detected by antivirus software?

Known keyloggers, yes; newer or custom-built ones may require EDR-type behavioral detection.

Does MFA protect against a keylogger?

It greatly limits the impact: even a captured password becomes insufficient if a second factor is required to log in.

Not ready to talk yet? Discover our cybersecurity assessment →

Is an account logging in unusually?

Contact us to investigate a possible credential compromise.