Spyware
Spyware is malicious software that covertly monitors a device — harvesting credentials, messages, and activity — and feeds social-engineering attacks.
Spyware is malicious software that covertly collects information from a device — passwords, messages, browsing activity, screenshots, files, sometimes microphone and camera feeds — and sends it to an attacker. Unlike ransomware, it succeeds by staying invisible: the longer it runs unnoticed, the more it harvests. The category spans crude "stealer" malware sold on criminal forums, keyloggers, stalkerware installed by someone with physical access, and commercial-grade implants used against executives, journalists, and officials.
How it works
Most corporate spyware infections begin with social engineering: a phishing attachment, a fake software update or installer promoted through malvertising or SEO poisoning, a cracked application, or a malicious browser extension. Once running, the spyware hooks the operating system or browser to capture keystrokes, saved passwords, session cookies, and clipboard contents, then exfiltrates them quietly.
The output is rarely the end goal — it is raw material. Stolen credentials and cookies are bundled into "stealer logs" and sold, fueling account takeover and letting attackers walk into corporate SaaS, email, and VPN accounts with valid sessions that bypass the login page entirely. Harvested mailbox contents also make later pretexts eerily convincing: an attacker who has read your invoices writes a very good fake one — the setup behind many of the incidents in our incident response guide.
How to defend against it
- Cut off the delivery channels. Application allow-listing, blocking unapproved browser extensions, and warning users about "free" software, cracked tools, and fake updates remove the most common install paths.
- Detect the behavior, not just the binary. EDR that flags credential-store access, unusual outbound connections, and browser-cookie theft catches stealers that signatures miss.
- Assume harvested credentials. Phishing-resistant MFA and short session lifetimes limit what a stolen password or cookie is worth; monitor for logins that skip the usual device fingerprint.
- Make the human layer sensitive to the lure. The install almost always requires a person to run something — security awareness training and realistic simulations keep that click from happening.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo