Skip to content
Keylogger

One keystroke.
Credentials captured.

A rigged USB cable, malware, a compromised browser extension: three vectors to silently capture every keystroke. With exfiltration to a C2 server and instant VPN access.

Real-time captureSimulated C2 terminalOMG CableRogue extension
hr-portal.company.com/login
Login — HR Portal
HR Portal — Login
Secured

Log in to your account

••••••••
Log in
✓ No keylogger — secure session
Step 1 of 4

A workstation like any other

The employee logs into their HR portal. No visible threat — the keylogger isn't active yet.

Every keystroke passes through the OS

Before reaching the browser or application, every key press goes through the operating system. It's precisely this layer that software keyloggers, booby-trapped USB cables, and malicious extensions intercept.

Key figures

~$0

Price of a Wi-Fi keylogger cable

undetectable, ready to use (OMG Cable)

0 trace

Detectable by antivirus

a hardware keylogger goes completely unnoticed

0 %

Of keystrokes captured

even on type="password" fields

0

Attack vectors

software · USB cable · browser extension

Advanced technical demo

Interactive simulator — three vectors

Type your own text and watch the capture live. Three tabs: software keylogger with C2 terminal, hardware USB interception, and malicious browser extension.

Interactive demonstration

Keylogger simulator

Typing simulator

Password reconstructed by the attacker

Waiting for input…

Attacker server — keylogger.log
LIVE

[SESSION] #4f2a9c1b · DESKTOP-RH4 · 192.168.1.42 · Win11 Pro

[USER] j.dupont · [PID] 3847 · [UPTIME] 00:14:32

Waiting for keystrokes…

Note: the keylogger captures every keystroke, even with a type="password" field. Visual masking has no effect on system-level interception.

Software keylogger

Malware installed via phishing, a booby-trapped USB drive, or pirated software. Runs in the background and exfiltrates keystrokes to the attacker's server.

Hardware keylogger

A physical device (USB, OMG Cable ~$180) placed between the keyboard and the PC. No software installed, undetectable by antivirus.

Malicious extension

A compromised browser extension that captures form fields before submission, bypassing HTTPS encryption.

How to protect against it

EDR / Antivirus

An Endpoint Detection & Response tool detects keystroke-capturing processes and isolates them before exfiltration.

MFA authentication

Even with the password, a second factor (TOTP, hardware key) blocks the attacker's access.

USB port control

Disable or restrict unauthorized USB ports in the company via GPO policy or EDR.

Extension auditing

Restrict browser extensions to sources approved by IT. Audit regularly.

Real-world example

Wi-Fi keylogger cable

Undetectable. ~$180.

A keylogger cable looks perfectly like a Samsung or Apple cable. It creates a discreet Wi-Fi hotspot that the attacker connects to from a smartphone to retrieve keystrokes in real time, with no trace left on the machine.

What you don't see

Device hidden inside a normal-looking USB cable

Built-in Wi-Fi hotspot active at all times

Silent transmission of keystrokes to an attacker's smartphone

Wi-Fi keylogger cable, OMG Cable type