← All terms

Spyware

Spyware is malicious software that covertly monitors a device — harvesting credentials, messages, and activity — and feeds social-engineering attacks.

Spyware is malicious software that covertly collects information from a device — passwords, messages, browsing activity, screenshots, files, sometimes microphone and camera feeds — and sends it to an attacker. Unlike ransomware, it succeeds by staying invisible: the longer it runs unnoticed, the more it harvests. The category spans crude "stealer" malware sold on criminal forums, keyloggers, stalkerware installed by someone with physical access, and commercial-grade implants used against executives, journalists, and officials.

How it works

Most corporate spyware infections begin with social engineering: a phishing attachment, a fake software update or installer promoted through malvertising or SEO poisoning, a cracked application, or a malicious browser extension. Once running, the spyware hooks the operating system or browser to capture keystrokes, saved passwords, session cookies, and clipboard contents, then exfiltrates them quietly.

The output is rarely the end goal — it is raw material. Stolen credentials and cookies are bundled into "stealer logs" and sold, fueling account takeover and letting attackers walk into corporate SaaS, email, and VPN accounts with valid sessions that bypass the login page entirely. Harvested mailbox contents also make later pretexts eerily convincing: an attacker who has read your invoices writes a very good fake one — the setup behind many of the incidents in our incident response guide.

How to defend against it

  • Cut off the delivery channels. Application allow-listing, blocking unapproved browser extensions, and warning users about "free" software, cracked tools, and fake updates remove the most common install paths.
  • Detect the behavior, not just the binary. EDR that flags credential-store access, unusual outbound connections, and browser-cookie theft catches stealers that signatures miss.
  • Assume harvested credentials. Phishing-resistant MFA and short session lifetimes limit what a stolen password or cookie is worth; monitor for logins that skip the usual device fingerprint.
  • Make the human layer sensitive to the lure. The install almost always requires a person to run something — security awareness training and realistic simulations keep that click from happening.

Related terms

KeyloggerA keylogger is software or hardware that secretly records keystrokes to steal passwords, messages, and card numbers, feeding credential-based attacks.RansomwareRansomware is malware that encrypts or steals an organization's data and demands payment, most often delivered through phishing and stolen credentials.MalvertisingMalvertising is the use of online advertising to spread malware or lead users to phishing pages, often through legitimate ad networks and search ads.Account Takeover (ATO)Account takeover is an attack in which a criminal gains control of a legitimate user account and operates it for fraud, theft, or further attacks.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo