A keylogger captures every keystroke made on a device and sends that information to an external source. In 2025, infostealer malware, including keyloggers, resulted in the theft of 642.4 million credentials from 13.2 million infections globally. In Australia, approximately 30,000 banking passwords were compromised between 2021 and 2025 due to this malware. The Australian Cyber Security Centre reported over 42,500 calls related to credential theft in one year, a 16% increase. Four main malware families dominate the landscape, with LummaC2 accounting for nearly 60% of credentials linked to infostealers in 2026. Keyloggers can be detected through signs such as typing lag, unexpected antivirus notifications, new browser extensions, and unexplained spikes in outbound data usage. Detection and removal steps include checking running processes, auditing startup programs, reviewing installed programs, running antivirus scans, and resetting passwords from a clean device. Keyloggers can infiltrate systems via phishing emails, malicious attachments, or compromised software downloads. Mobile devices can also be targeted by keyloggers disguised as legitimate apps.