northdan.
Vezi pagina în română

IT Glossary

What is spyware?

Spy software: installed in secret, it transmits what it sees — passwords, keystrokes, screens, conversations — with no noisy symptoms at all.

Ransomware announces its arrival with fanfare; spyware only works if nobody notices it exists. The category covers software installed covertly that collects and transmits what happens on a device — typed passwords, screens, files, conversations, location. Ranked by relevance to companies, the fauna starts with infostealers, the sad stars of recent years: programs that arrive through attachments, cracked software or poisoned adverts, harvest everything valuable on a workstation within minutes — passwords saved in browsers above all, plus session cookies, which let an attacker enter accounts without the password and sometimes past two-factor authentication — then vanish towards the markets where corporate access is sold wholesale. Batches of fresh credentials from these infections are the raw material behind many apparently inexplicable business account breaches. After them come keyloggers, remote access trojans that hand over an entire machine including camera and microphone, and stalkerware, the commercial surveillance applications installed by somebody with physical access to a phone. Because symptoms are usually absent, the defence is calibrated differently from the rest of security: prevention first, through clean software sources, patching and behavioural endpoint detection; damage limitation by architecture, meaning a password manager instead of browser-stored passwords and two-factor authentication everywhere; and detection through indirect signs in the accounts themselves rather than on the machine.

Let’s talk about your project

Message us on WhatsApp or send an email — you talk directly to a developer.

office@northdan.com · +40 752 070 247

Why it matters for your business

Company passwords out of harvesting range

A password manager plus two-factor authentication mean an infostealer reaching one workstation leaves with far less; architecture limits the damage before detection happens.

Exfiltration caught by behaviour

Modern endpoint detection spots suspicious collection and transmission even from previously unseen variants — precisely what signature-based antivirus used to miss.

Accounts watched from the outside

Periodic review of logins and active sessions catches the consequence of spying, which is foreign access, even when the infection itself stayed invisible.

Frequently asked questions

How would I know I have spyware if it produces no symptoms?

Rarely from the machine itself — the useful signs live in the accounts: logins from unfamiliar cities or devices, which the security pages of the major providers list; unknown active sessions; forwarding rules that appeared in the mailbox; alerts from services about compromised passwords. Add periodic scans with serious endpoint tooling. The correct reflex at any signal inverts instinct: assume the machine you are working on is compromised and change the passwords from a different device.

An employee installed a free program and foreign logins appeared next day — what is the connection?

Almost certainly an infostealer bundled with pirated or counterfeit software: the harvest of browser passwords and session cookies was sold or used within hours, which is where the logins came from. The response is isolating the machine, changing every password used on it from a clean device, invalidating all sessions, checking mailbox rules and two-factor settings, then reinstalling. The policy lesson is that software sources get controlled — restricted install rights plus an approved tool list stop the entire category.

Is it legal to monitor what employees do on company computers?

With transparency and proportionality, yes, within limits: written policies stating what is monitored and why, means proportionate to the purpose — access logs and filtering are defensible, continuous screen capture, keystroke logging and camera access almost never are — and a documented legitimate interest. Covert spyware-style monitoring is illegal regardless of who owns the equipment, exposed to data protection penalties and criminal liability. If a tool is installed so that employees will not know, the legal answer is already no.