One keystroke.
Credentials captured.
A rigged USB cable, malware, a compromised browser extension: three vectors to silently capture every keystroke. With exfiltration to a C2 server and instant VPN access.
A workstation like any other
The employee logs into their HR portal. No visible threat — the keylogger isn't active yet.
Every keystroke passes through the OS
Before reaching the browser or application, every key press goes through the operating system. It's precisely this layer that software keyloggers, booby-trapped USB cables, and malicious extensions intercept.
Key figures
~$0
Price of a Wi-Fi keylogger cable
undetectable, ready to use (OMG Cable)
0 trace
Detectable by antivirus
a hardware keylogger goes completely unnoticed
0 %
Of keystrokes captured
even on type="password" fields
0
Attack vectors
software · USB cable · browser extension
Advanced technical demo
Interactive simulator — three vectors
Type your own text and watch the capture live. Three tabs: software keylogger with C2 terminal, hardware USB interception, and malicious browser extension.
Interactive demonstration
Keylogger simulator
Typing simulator
Password reconstructed by the attacker
Waiting for input…
[SESSION] #4f2a9c1b · DESKTOP-RH4 · 192.168.1.42 · Win11 Pro
[USER] j.dupont · [PID] 3847 · [UPTIME] 00:14:32
Note: the keylogger captures every keystroke, even with a type="password" field. Visual masking has no effect on system-level interception.
Software keylogger
Malware installed via phishing, a booby-trapped USB drive, or pirated software. Runs in the background and exfiltrates keystrokes to the attacker's server.
Hardware keylogger
A physical device (USB, OMG Cable ~$180) placed between the keyboard and the PC. No software installed, undetectable by antivirus.
Malicious extension
A compromised browser extension that captures form fields before submission, bypassing HTTPS encryption.
How to protect against it
EDR / Antivirus
An Endpoint Detection & Response tool detects keystroke-capturing processes and isolates them before exfiltration.
MFA authentication
Even with the password, a second factor (TOTP, hardware key) blocks the attacker's access.
USB port control
Disable or restrict unauthorized USB ports in the company via GPO policy or EDR.
Extension auditing
Restrict browser extensions to sources approved by IT. Audit regularly.
Real-world example
Wi-Fi keylogger cable
Undetectable. ~$180.
A keylogger cable looks perfectly like a Samsung or Apple cable. It creates a discreet Wi-Fi hotspot that the attacker connects to from a smartphone to retrieve keystrokes in real time, with no trace left on the machine.
What you don't see
→Device hidden inside a normal-looking USB cable
→Built-in Wi-Fi hotspot active at all times
→Silent transmission of keystrokes to an attacker's smartphone
