Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is spyware?

Spyware is software used to collect information about a device or its user without proper authority or informed consent.

It may monitor location, messages, browsing, keystrokes, screens, files, microphone or camera activity. The investigation needs to establish which functions were available, which were active and where the collected information went.

Follow the monitoring relationship

Consider a fictional Android phone with an application presented as Family Locator. Device records show the app installed from outside the organisation's approved route and communicating regularly with a remote service. Its app permissions—the operating-system settings that allow an app to use particular device data or functions—include location permission, and it also has an enabled accessibility service. A separate portal account is associated with the phone and is capable of viewing collected information.

InstallationHow did the app reach the phone?Package, source, installer account and time.
AccessWhat could it reach?Permissions, accessibility service, device role and configuration.
CollectionWhat did it actually capture?Local databases, caches, notifications or recorded events.
TransmissionWhere did data go?Destination, timing, volume and service records.
ControlWho could view or direct it?Portal account, subscription, payment and access history.

The application name and facts are fictional. They show the evidence chain rather than a specific commercial product.

Permissions describe opportunity, not completed collection

On Android, permissions and special access help define what an app may be allowed to do. They do not prove that every permitted function ran.

For example:

Finding Useful meaning Next comparison
Location permission granted The app had an authorised technical route to location, subject to platform state and scope App activity, location records and transmission events
Accessibility service enabled The app obtained a powerful interaction route Configuration, captured content and resulting actions
Microphone permission present Audio capture may have been possible Recording artefacts, active-use indicators and network activity
Controller portal account An available route existed to view or manage collected data Account creation, sign-ins, access events, payment and device association

Keep the exact platform version, application package, permission state and relevant period. Permission models and labels can change between operating-system versions.

Authority is part of the technical picture

Monitoring software can have legitimate uses in managed workplaces, child-safety arrangements and device administration. A familiar product name does not settle whether this installation and use were authorised.

Identify:

  • who installed or commissioned it;
  • what notice and consent existed;
  • which device, user and period the authority covered;
  • which functions were enabled;
  • who controlled the monitoring account; and
  • whether use stayed within the stated purpose.

That separates a legitimate product from an unauthorised deployment without assuming that either the vendor or device owner controlled the relevant activity.

Missing local output does not automatically end the enquiry. Data may have been transmitted, synchronised to a portal or deleted. Network, provider, subscription and controller-account records may preserve the other side of the monitoring relationship. The account's existence establishes an available control route; it does not prove that somebody signed in or accessed particular collected data.

Keylogging is one possible collection function. Information stealers are usually framed around acquiring valuable stored data; spyware is the broader monitoring relationship and can operate over time.

The strongest account follows the monitoring chain from installation and available access through actual collection and transmission to a recorded controller session. Stop at the last supported stage: capability does not show what was captured, and an available portal does not show who viewed it.

Technical sources - checked 27 September 2026
Reference: CIM-067Cyber Incidents & Offender Methods