Skip to content

Keylogger

In plain terms

A device that records everything you type on the keyboard. Including what you delete before sending, and what you type on perfectly genuine websites.

Definition

A keylogger is a device — software, or a small piece of hardware inserted on the keyboard port — that captures the keys typed on a device and sends them to a third party. Its distinctive feature is that it works upstream of any website: whether the page you're typing on is legitimate makes no difference.

How it works

The software version installs like other malware and places itself between the keyboard and the system: it sees the keystrokes before the app that receives them. The hardware version is a discreet unit plugged in between the keyboard and the computer, which limits it to devices physically accessible to others — a shared computer, a publicly accessible machine, an open desk. In both cases, what sets this method apart is its scope: it captures the correct password typed on the real site, the sentence started then deleted, the message never sent, the code copied from a notebook. Protections based on the idea of avoiding a fraudulent site have no purchase here, since there is no fake site.

Warning signs

  • Small box or unusual adapter between the keyboard cable and the computer
  • Logins to your accounts from places or devices you don't recognize
  • Accounts compromised despite not having clicked any link or reused any password
  • On a shared computer, a session already open or an unknown program at startup
  • Lag or stutter while typing, inconsistent and not conclusive on its own

How to verify

On a desktop computer whose physical access isn't guaranteed, check what's plugged in behind the machine — it's the only genuinely conclusive check in this entry. On the software side, review the programs launched at startup and accessibility permissions, which is the mechanism usually hijacked. On a computer you don't control, treat the question as undecidable and don't type anything sensitive into it.

What to do

Don't type an important password on a shared or public computer. Enable two-factor authentication: it's what limits the damage best here, since a captured password is no longer enough on its own. A password manager that fills in fields without going through the keyboard also reduces exposure.

If it already happened

From another device, change the passwords of accounts used on the suspect machine, starting with your main email account, and close open sessions. If a hardware keylogger is found, don't remove it before photographing the setup: it's evidence to include with a police report. On a work computer, notify IT before doing anything. Report the incident to cybermalveillance.gouv.fr.

Frequently asked questions

Does two-factor authentication really protect you?
It prevents a captured password alone from being enough, which is already the main point. It doesn't make an account unbreakable: a one-time code typed on the keyboard is captured like everything else, and is only valid for a few moments. A physical security key or approval in a dedicated app don't go through the keyboard and so aren't exposed this way.
Does copy-pasting my password avoid capture?
Not reliably: the clipboard is also accessible to a program installed on the machine. The useful reasoning isn't how to get around capture on a compromised device, but not entering sensitive information on a device you can't vouch for.

Official sources

Also known as: keylogger, keystroke logger, keystroke capture.

This article is part of the Malware family. Last updated: 2026-09-03.