Spyware is software that collects data from a computer user and forwards this data without the user’s knowledge or consent. The term is made up of the word “spy” and the ending “ware” (as a term for computer programs/software). Other terms in German are spying program, espionage or snooping software.
A computer can become infected in the same way as with any other malware. This may happen through infected e-mail attachments, security vulnerabilities in a system, infected removable storage devices such as USB sticks or external hard drives, malicious add-ons in fake software installations, and the list goes on. Trojans or worms often also come with spyware.
Once installed, the spyware begins collecting data in the background. Once a connection to the Internet is established, the collected data is transmitted. Spyware is often developed by companies to analyze user behavior, especially surfing behavior on the Internet, in order to display targeted advertising banners or pop-ups. These practices are considered unfair and are often illegal. Criminals, on the other hand, are more likely to target confidential information such as credit card details, passwords or account information. But spyware can also be used to collect biometric data or webcam activity.
Spyware is an umbrella term for various types of software that differ in the way they function and the type of information they collect.
- Adware uses the websites visited and the search history to create a user profile for the purpose of displaying unwanted advertising.
- Tracking cookies record internet activities and habits in order to better target advertising or to sell the data to third parties.
- Keyloggers record all user activity, including passwords, messages and other sensitive information, providing criminals with a wealth of information.
- System monitoring tools track all computer activity. From open programs to real-time screen recordings, they provide a comprehensive overview.
- Password stealers are programs that specifically target passwords. From passwords stored in browsers to system logins or other password-protected applications.