Flamingo Raises $4.5M Seed Round

Skip to content

A laptop that feels a little slower, a browser toolbar nobody remembers adding, a sign-in alert from a city nobody has visited. Spyware rarely announces itself, because staying hidden is the whole job. Here's what spyware is, what spyware does once it lands on a phone or computer, and what IT should do the moment it turns up.

What Is Spyware?

Spyware is software that watches what happens on a device and sends it to someone else, without the owner knowing. NIST's security glossary defines it as software "secretly or surreptitiously installed into a system to gather information on individuals or organizations without their knowledge."

It's one branch of the wider malware family. Ransomware wants to be seen, because the ransom note is the business model. Spyware wants the opposite: the longer it runs unnoticed, the more it collects. Our guide to what malware is covers the other branches.

Some spyware is sold openly as "monitoring" software and installed by someone with physical access. Some arrives inside a fake installer. A small amount is built by commercial surveillance vendors and aimed at specific people. The label covers all of it, and the defining trait is the same: data leaves the device without consent.

What Does Spyware Do?

Spyware collects, then ships what it collects to a server the attacker controls. What it collects depends on the family, but the list usually includes:

  • Keystrokes, including passwords typed into login pages
  • Saved passwords pulled from browsers and password stores
  • Browser cookies and session tokens, the proof that you already signed in
  • Screenshots, clipboard contents and files from common folders
  • Messages, call logs, location, microphone and camera on phones

For a person, that's a privacy problem. For a business, the most expensive item on that list is usually the session token. A stolen password still has to get past MFA. A stolen session often doesn't, because the sign-in and the MFA check already happened on the victim's device.

Types of Spyware

Spyware families differ in who they target and what they're after. Five show up again and again.

Infostealers. Mass-market spyware that runs once or briefly, grabs saved passwords, cookies, crypto wallets and system details, and uploads the lot. Stolen logs are sold in bulk. Microsoft named Emotet, Redline and IcedID among the families that extract browser cookies.

Keyloggers. Record every keystroke, sometimes with screenshots. Older than infostealers and still common inside larger malware kits.

Stalkerware. Commercial "monitoring" apps installed on a partner's or relative's phone to track messages and location. In 2021 the FTC banned SpyFone and its CEO from the surveillance business, the first FTC case to win such a ban.

Adware and tracking software. Browser extensions and bundled "free" tools that record browsing history and sell it or inject ads. Lower stakes, but the same permissions a spy tool needs.

Mercenary spyware. Built by commercial vendors and sold to governments. Citizen Lab showed in September 2021 that NSO Group's Pegasus reached iPhones through a zero-click exploit in iMessage, patched in iOS 14.8. Rare, targeted and expensive.

Spyware also rides inside other malware. A remote access trojan often carries a keylogger or screen-capture module as one feature among many.

Spyware vs Monitoring Software at Work

Companies install monitoring tools on work devices too: endpoint agents, device management, data loss prevention, sometimes screen or activity recording. The software can look similar. What separates it from spyware is ownership, disclosure and consent.

Monitoring a company-owned device under a written policy that staff have seen is administration. The same tool installed on someone's personal phone without their knowledge is spyware, whatever the vendor calls it. Rules on workplace monitoring differ by country and state, so the policy belongs with HR and legal, not only with IT.

For IT teams, the practical test is simple. Every agent on a device should be one you deployed, can name and can remove. Anything collecting data that nobody on the team installed is an incident.

Why a Stolen Session Beats a Stolen Password

Microsoft's incident response team wrote in 2022 that when an attacker replays a token issued after MFA, it "satisfies the validation of MFA." The attacker doesn't see a prompt, because the account already answered one.

That changes the cleanup. Resetting a password doesn't always end a session that's already open. Neither does wiping the laptop the cookies came from. The session lives in the cloud service, and it has to be revoked there.

Sysadmins trade notes on this in threads like the one below, where the question is what defenses hold up once a session cookie has left the building.

David Bombal's demo walks through a cookie theft end to end, including why the second factor never comes up.

How Spyware Gets on a Device

Spyware needs a way in, and it usually needs a person to open the door. The common routes are email attachments and links that install a loader, fake installers and cracked software found through search ads, and browser extensions that ask for access to every site. Stalkerware usually arrives through a few minutes of physical access to a phone that isn't locked. Unpatched software, and in rare targeted cases a zero-click exploit, needs no help at all.

The shared weak point is permission. A user who can install anything, or an extension that can read every page, gives spyware the same access the user has. Reused credentials make it worse: one stolen login opens every account that shares it, which is why the most common passwords are an attacker's first guess after a leak.

Signs of Spyware

Good spyware leaves few symptoms. When it does show, it tends to look like this:

  • Sign-in alerts or MFA prompts nobody triggered
  • New browser extensions, toolbars or a changed homepage
  • A device that runs hot, drains battery or uses data while idle
  • Accounts showing activity from new locations or devices
  • Unfamiliar apps with accessibility or device admin rights on a phone

None of these proves spyware on its own. Infostealers often run once and delete themselves, so the first sign may be a login from elsewhere days later. Phone owners ask the same question in threads like this one.

What to Do If You Find Spyware

Treat spyware as a credential incident first and a malware cleanup second. The order matters.

  1. Isolate the device from the network so it stops sending data.
  2. Identify the family from the detection name. An infostealer means credentials and sessions are already gone.
  3. Revoke active sessions for every account used on that device, in each cloud service.
  4. Reset passwords from a clean device, starting with email, identity provider and admin accounts. Check MFA methods and mailbox rules for anything the attacker added.
  5. Clean or reimage the device. For infostealers and remote access tools, a reimage is the safer call.
  6. Review what was accessed while the sessions were live.

Our upcoming guide on how to remove malware from a PC covers the cleanup step in detail.

How to Prevent Spyware

Prevention works on the same two fronts: keep spyware off the device, and make whatever it steals worth less.

Limit what users can install. Remove local admin rights and allow browser extensions by policy, not by request.

Patch the browser and OS quickly. Exploits against browsers and phones are the entry point that needs no click.

Make stolen sessions harder to replay. Microsoft's mitigations include phishing-resistant MFA, compliant-device checks, shorter token lifetimes and continuous access evaluation. Its Token Protection feature binds sign-in tokens to the device they were issued to.

Protect the people most likely to be targeted. Apple's Lockdown Mode exists for the few people who may be personally targeted by mercenary spyware.

Check what's installed. In OpenFrame, the open, AI-native infrastructure layer for IT and security, a technician can run one script across a client's devices to list browser extensions and startup items, with the output collected in one place.

Kristina Shkriabina

Content Marketing Lead

Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

What Is Spyware

Often, yes. Infostealers copy the session cookies a browser keeps after you sign in, and an attacker who replays one skips the MFA prompt because the check already happened. Revoking active sessions ends that access. Phishing-resistant MFA and features that bind tokens to a device make stolen sessions harder to reuse.
No. Both are malware, but a virus copies itself into other files, while spyware watches a device and sends what it collects to someone else. Spyware often arrives inside a trojan or a fake installer rather than spreading on its own.
A factory reset or a reimage removes most spyware from the device itself. It does nothing about what already left: stolen passwords and session tokens stay valid until they're reset and revoked in each service. Do both.
Update the operating system, then review installed apps and anything with accessibility or device admin rights on Android, or unknown profiles under VPN and Device Management on iPhone. Check which devices are signed in to your email and cloud accounts. If you suspect someone close to you installed stalkerware, removing it may alert them, so plan for your safety before you do.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.