How it works
A keylogger records keyboard input rather than merely observing network traffic. It may be software on the computer or a physical device in the keyboard path. Its purpose can be to capture passwords or other typed information without the user’s informed permission.
A practical example
A person can enter a password on the genuine bank website over HTTPS while a compromised computer records the keystrokes locally. The encrypted web connection protects transport, but it cannot prevent malicious software on that same endpoint from observing input before transmission.
What to check
If a keylogger is suspected, avoid signing in to sensitive accounts on that device. Use a separate trusted device to review account sessions and change exposed credentials. Record the suspicious programme or detection and arrange a device assessment; inspect unfamiliar keyboard adapters without dismantling unfamiliar hardware.
Limits and safe use
Slow typing or a stuck key is not evidence of a keylogger: ordinary keyboard faults need separate diagnosis. An on-screen keyboard is not a universal defence against malware. Account recovery and device cleaning are distinct steps; removing one detected component does not automatically invalidate credentials already stolen.