Spyware

Sec+ Glossary 📖 • Threats ⚠️ • Security+ 02 Difficulty: free

What is Spyware?

Spyware is malware that secretly monitors a device or user activity and collects information such as credentials, messages, browsing behavior, or sensitive files. It is designed to stay hidden while sending collected data to an attacker or another unauthorized party.

Examples

  • A fake browser extension records browsing activity and sends it to an external server without the user’s knowledge.
  • A keylogger captures login details entered on a compromised laptop and forwards them to an attacker.

Discover 🔎

Spyware is built for observation. Instead of immediately causing obvious damage, it tries to blend into normal activity and quietly collect information over time. That makes it dangerous, because victims may not notice anything wrong until accounts are taken over, data is leaked, or sensitive information is used for fraud.

Spyware also matters because it can appear in different forms. Some spyware is clearly criminal and designed for theft. Other spyware is packaged as “monitoring” software and ends up being used in abusive or unauthorized ways.

Remember: Spyware is about surveillance and data collection. Its goal is to learn, steal, and report, while staying unnoticed.

Summary 📝

Spyware is malware designed to secretly monitor activity and steal information, often focusing on credentials, browsing data, communications, and sensitive files. It commonly spreads through phishing, bundled software, and untrusted extensions, and it aims to remain hidden while exfiltrating data. Defending against spyware involves controlling software installation, hardening browsers, using endpoint monitoring, and treating credential resets as a core part of response.

Open the interactive lesson Browse more topics

Tip: The interactive version includes progress tracking, decks, and premium deep dives.