Spyware
In short: Malicious software that secretly collects information about a device or its user and sends it to third parties — keystrokes, location, messages, camera/microphone.
In more detail: Unlike ransomware, which aims for quick financial gain, spyware usually operates as inconspicuously as possible over a longer period, to continuously extract data. Ranges from simple advertising-tracking software to highly sophisticated, state-deployed surveillance tools such as Pegasus.
In Depth
Spyware can be roughly distinguished by target group and sophistication:
Commercial ad trackers - collect browsing behaviour for targeted advertising,
often (semi-)legally hidden in terms of use
Keyloggers - record keystrokes (passwords, messages)
Consumer spyware/stalkerware - e.g. for secretly monitoring a partner/employee
State spyware - highly sophisticated, e.g. Pegasus, often
installable via zero-day holes with no user
interaction at all
The decisive difference from “simple” ad-tracking software is the degree of stealth and depth of access: while tracking cookies are visible in the browser and (with effort) blockable, real spyware often nests deep in the operating system, disguises itself as a legitimate system process and can be difficult or impossible for normal antivirus software to detect — especially with state-funded variants, which often exploit previously unknown vulnerabilities (zero-days) for which no detection signature yet exists.
Typical infection routes are tampered app installations, phishing links, or with highly sophisticated spyware, so-called “zero-click” attacks, where no interaction from the victim is needed at all (e.g. a prepared message that exploits a vulnerability the moment it’s merely received). Protective measures range from basic hygiene (apps only from official stores, keeping the operating system/apps up to date) to specialised detection tools for sophisticated spyware, provided by security research organisations.
Commercial surveillance software as its own industry
Alongside classic criminal spyware, there’s a legal but ethically controversial market for commercial surveillance software (“spyware-as-a-service”): companies like NSO Group (the maker of Pegasus) officially sell highly sophisticated spy tools only to governments and law enforcement agencies for fighting terrorism and serious crime — but it has repeatedly been documented that such tools were also used against journalists, human rights activists and political opposition figures, which has led to international controversy, export restrictions and sanctions against individual manufacturers.
Detection and defence
Because sophisticated spyware is often specifically designed to evade conventional antivirus detection, security researchers increasingly rely on forensic analysis instead of pure signature detection: organisations like Citizen Lab (University of Toronto) or Amnesty International’s Security Lab specifically examine suspicious devices for traces of known spyware families, such as unusual network connections to known command servers or telltale artefacts in the file system that would go undetected in a normal, superficial check. For the average user, the most effective defence remains mundane: keep the operating system and apps updated promptly (many spyware infections exploit known but unpatched holes) and critically question permission requests from apps (camera, microphone, location).
The difference from adware
Spyware is often confused with adware, but differs in its core goal: adware primarily displays unwanted advertising and finances itself through that, often without specifically harvesting personal data — annoying, but usually less dangerous. Spyware, on the other hand, has secret data collection itself as its main purpose, regardless of whether advertising is involved at all. In practice, the two categories overlap frequently, since many ad networks also collect detailed user profiles for “personalised advertising”, blurring the line between legitimate tracking and spyware in a grey area.