The university of tulsa Online Blog

Trending topics in the tu online community

Cyber Security

What Is Keylogging?

Written by: University of Tulsa   •  Aug 27, 2026

Hands type on a laptop keyboard.

Cyber attackers employ a range of stealthy yet effective techniques, and keylogging is one that often underlies successful attacks. Keylogging captures users’ keystrokes before encryption or multi-factor authentication (MFA) can protect the data. Cybercriminals commonly use this method.

  • The 2025 Verizon Data Breach Investigations Report found that stolen credentials are a common cause of breaches (22% of cases) — and often, credential theft begins with keystroke capture.

  • Check Point’s The State of Cyber Security 2025 found that infostealer activity — the broader category for keylogging — surged 58% year over year.

For anyone in cybersecurity, knowing how keyloggers operate, where they hide, and how to stop them is essential. An advanced degree, such as a Master of Science (M.S.) in Cyber Security, helps professionals learn how to defend against exploits like these and protect organizations from cyber threats.

Definition and Types of Keylogging

Keylogging is the process of recording keystrokes. The National Institute of Standards and Technology (NIST) defines a keylogger as a program that tracks the keys pressed on a keyboard. This can be used to recover passwords or encryption keys and to circumvent other security measures.

Cybercriminals often use keylogging to access sensitive information. Although it’s primarily a tool for cyber theft, it can also help organizations reduce risks.

There are two main types of keyloggers: software and hardware.

Software Keyloggers

Software keyloggers use browser-based keyloggers (JavaScript, web form input) and system-level keyloggers (kernel-based, at the operating system level). By reading input directly from the keyboard, they intercept data before the HTTPS encryption process takes effect. After the information is captured, keystrokes are sent to the attacker via email, file transfer, web requests, or a remote access Trojan that streams logs in real time.

Hardware Keyloggers

Hardware keyloggers require attackers to have physical access to their target machines — for example, by attaching a modified keyboard or an inline device that saves or forwards keystrokes. Another option is for attackers to use wireless interceptors to eavesdrop on signals from Bluetooth or radio frequency keyboards.

Keylogging Examples

Knowing how keyloggers work and what intrusions can look like from end to end helps cybersecurity professionals recognize patterns before serious damage can be done.

How Keyloggers Access Devices

Keyloggers use several strategies to infiltrate different devices.

  • Most keyloggers reach their target devices through tried-and-true methods, such as phishing emails with malicious attachments or links.

  • Users can unknowingly grant keyloggers access by downloading from compromised websites that deliver malware, including viruses and Trojan horses bundled with unofficial software.

  • Keyloggers can also be delivered through Trojan horses installed remotely. On some occasions, attackers physically install malicious software on shared public computers, making physical security, such as cameras, an important strategy for defending against these types of attacks.

A real-world example, Snake Keylogger, offers insights into how keylogger attacks can unfold.

  • A user receives a phishing email with what appears to be a routine payment notification. A Microsoft Excel file is attached, which, when opened, silently triggers a multistage infection.

  • A known Microsoft Office vulnerability quietly downloads a script file, which in turn loads PowerShell code that installs Snake Keylogger on the device.

That’s all it takes for the malware to harvest saved credentials from applications, including browsers, email clients, File Transfer Protocol (FTP) tools, and instant messengers. It then transmits the stolen data back to the attacker over Simple Mail Transfer Protocol (SMTP). The victim notices nothing unusual until their accounts start showing fraudulent activity.

How Cybersecurity Professionals Defend Against Keyloggers

Effective defense starts with knowing what keylogging is and recognizing the signs that it’s taking place. These can include:

  • Unexplained typing delays

  • Applications freezing without reason

  • Unfamiliar processes in Task Manager

  • Unexpected network traffic when apps are offline

  • Unexpectedly disabled security software

Employees using company devices should be aware of keylogging and alert to its signs. Security training in topics such as protecting personal information and preventing social engineering attacks is an important component of any cybersecurity strategy.

Cybersecurity professionals have various ways to defend against keyloggers before, during, and after attacks, including:

  • Endpoint detection and response tools that detect suspicious behavior and keylogger signatures

  • Anti-malware software with real-time monitoring

  • MFA, a cybersecurity method that asks users for at least two different ways to verify their identities and can block an attacker even after a password is captured

  • Password managers that autofill credentials, bypassing keyboards

  • On-screen keyboards for sensitive entries

  • Regular software patching to close the vulnerabilities that keyloggers rely on

Other strategies include establishing Zero Trust architecture, a cybersecurity framework that requires verification at every step, and implementing strong identity and access management (IAM) practices to limit damage when credentials are stolen.

Build a Career That Defends Against Threats

Keylogging is a cybersecurity vulnerability that works because it’s quiet — most users won’t even notice they’ve been compromised until it’s too late. However, because it can have such an outsized impact, organizations are always looking for professionals who understand what keylogging is and how it fits into the wider credential-theft economy.

If you want to develop an advanced technical foundation in network security, malware analysis, and incident response, The University of Tulsa’s Online M.S. in Cyber Security program can prepare you for senior-level positions. The curriculum focuses on preparing students with skills and knowledge of:

  • Sociotechnical system security, including malware, keylogging, and data loss

  • Human, economic, legal, and ethical factors involved with cyber attacks

  • Modern defensive cybersecurity technologies

  • Network security design and cryptography

In as little as 20 months, you can develop the skills that employers value. Learn how TU can help you advance your career in information security.

Recommended Readings

Data Breach Prevention: Tips for Cybersecurity Professionals

Understanding the Stages of the Cyber Kill Chain

Everything You Need to Know About Cybersecurity Regulations

Sources:

Check Point, Check Point Software’s 2025 Security Report Finds Alarming 44% Increase in Cyber-Attacks Amid Maturing Cyber Threat Ecosystem

CompTIA, 7 Most Common Types of Malware

Fortinet, “Deep Analysis of Snake Keylogger’s New Variant”

Fortinet, What Is a Keylogger? Definition and Types

IEEE Xplore, “Keylogger Detection: A Systematic Review”

Microsoft, What Is a Keylogger?

National Institute of Standards and Technology, Key Logger

Radware, Keylogging

Verizon, “Additional 2025 DBIR Research on Credential Stuffing”
Verizon, 2026 Data Breach Investigations Report

WeLiveSecurity, “SnakeStealer: How It Preys On Personal Data — and How You Can Protect Yourself”

Learn more about the benefits of receiving your degree from The University of Tulsa

Get More Information
Edit this page