It may capture credentials, keystrokes, messages, screens, location, browsing, files, audio, or device details. Covert monitoring and the resulting privacy or security violation are its defining features.
Spyware may be hidden in another application, exploit a vulnerability, abuse accessibility or administrative permissions, or be installed through physical access. It can store data locally or transmit it. The same specimen may also be a keylogger, information stealer, stalkerware, or Trojan horse.
Key points
Access and collectionDetermine how the software was installed, which permissions it holds, what sensors and data it can reach, when collection began, and where information was stored or sent.
DetectionReview application provenance, permissions, persistence, device-management state, unusual data access, network destinations, and discrepancies between the visible interface and observed behavior.
ResponseConsider account and credential exposure as well as the device, preserve necessary evidence, remove unauthorized access safely, and assess recipients and onward use of collected information.
Important limitationMonitoring software is not automatically spyware, but authorization by a device owner or employer does not by itself make monitoring lawful, proportionate, or adequately disclosed. In interpersonal-abuse cases, removal may alert the operator or destroy evidence, so personal safety should guide action.