ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1056.001×

126 examples

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareRCSession

RCSession has the ability to capture keystrokes on a compromised host.

T1056.001
Keylogging
Malwareyty

yty uses a keylogger plugin to gather keystrokes.

T1056.001
Keylogging
MalwareDOGCALL

DOGCALL is capable of logging keystrokes.

T1056.001
Keylogging
MalwarePAKLOG

PAKLOG has captured keystrokes using Windows API.

T1056.001
Keylogging
MalwareZeus Panda

Zeus Panda can perform keylogging on the victim’s machine by hooking the functions TranslateMessage and WM_KEYDOWN.

T1056.001
Keylogging
MalwareMatryoshka

Matryoshka is capable of keylogging.

T1056.001
Keylogging
MalwareInvisibleFerret

InvisibleFerret has conducted keylogging using the Python project “pyWinHook” and "Pyhook". InvisibleFerret has also captured keylogging thread checks for changes in an active window and key presses.

T1056.001
Keylogging
MalwareTONESHELL

TONESHELL has capabilities to conduct keylogging.

T1056.001
Keylogging
MalwareKasidet

Kasidet has the ability to initiate keylogging.

T1056.001
Keylogging
MalwareAppleSeed

AppleSeed can use GetKeyState and GetKeyboardState to capture keystrokes on the victim’s machine.

T1056.001
Keylogging
MalwareNETWIRE

NETWIRE can perform keylogging.

T1056.001
Keylogging
MalwareBOOKWORM

BOOKWORM has used its KBLogger.dll module to capture keystrokes and stored them in a folder.

T1056.001
Keylogging
MalwareCosmicDuke

CosmicDuke uses a keylogger.

T1056.001
Keylogging
MalwareEvilGrab

EvilGrab has the capability to capture keystrokes.

T1056.001
Keylogging
MalwareSslMM

SslMM creates a new thread implementing a keylogging facility using Windows Keyboard Accelerators.

T1056.001
Keylogging
MalwareGreyEnergy

GreyEnergy has a module to harvest pressed keystrokes.

T1056.001
Keylogging
MalwareCrimson

Crimson can use a module to perform keylogging on compromised hosts.

T1056.001
Keylogging
MalwareDUSTTRAP

DUSTTRAP can perform keylogging operations.

T1056.001
Keylogging
MalwareMachete

Machete logs keystrokes from the victim’s machine.

T1056.001
Keylogging
MalwarePowerLess

PowerLess can use a module to log keystrokes.

T1056.001
Keylogging
MalwarePrikormka

Prikormka contains a keylogger module that collects keystrokes and the titles of foreground windows.

T1056.001
Keylogging
MalwareHexEval Loader

HexEval Loader has utilized a cross-platform keylogger that has the capability to capture keystrokes on Windows, macOS and Linux systems.

T1056.001
Keylogging
MalwareFlawedAmmyy

FlawedAmmyy can collect keyboard events.

T1056.001
Keylogging
MalwareInvisiMole

InvisiMole can capture keystrokes on a compromised host.

T1056.001
Keylogging
MalwareOkrum

Okrum was seen using a keylogger tool to capture keystrokes.

T1056.001
Keylogging
MalwareRegin

Regin contains a keylogger.

T1056.001
Keylogging
MalwareMispadu

Mispadu can log keystrokes on the victim's machine.

T1056.001
Keylogging
MalwareFysbis

Fysbis can perform keylogging.

T1056.001
Keylogging
MalwareVERMIN

VERMIN collects keystrokes from the victim machine.

T1056.001
Keylogging
MalwareMarkiRAT

MarkiRAT can capture all keystrokes on a compromised host.

T1056.001
Keylogging
MalwareNavRAT

NavRAT logs the keystrokes on the targeted system.

T1056.001
Keylogging
MalwareDarkComet

DarkComet has a keylogging capability.

T1056.001
Keylogging
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has the ability to support keylogging.

T1056.001
Keylogging
MalwareBlackEnergy

BlackEnergy has run a keylogger plug-in on a victim.

T1056.001
Keylogging
MalwareXAgentOSX

XAgentOSX contains keylogging functionality that will monitor for active application windows and write them to the log, it can handle special characters, and it will buffer by default 50 characters before sending them out over the C2 infrastructure.

T1056.001
Keylogging
MalwareKeyBoy

KeyBoy installs a keylogger for intercepting credentials and keystrokes.

T1056.001
Keylogging
MalwareDarkTortilla

DarkTortilla can download a keylogging module.

T1056.001
Keylogging
MalwareROKRAT

ROKRAT can use `SetWindowsHookEx` and `GetKeyNameText` to capture keystrokes.

T1056.001
Keylogging
MalwareRunningRAT

RunningRAT captures keystrokes and sends them back to the C2 server.

T1056.001
Keylogging
MalwareDarkWatchman

DarkWatchman can track key presses with a keylogger module.

T1056.001
Keylogging
MalwarePlugX

PlugX has a module for capturing keystrokes per process including window titles.

T1056.001
Keylogging
MalwareDustySky

DustySky contains a keylogger.

T1056.001
Keylogging
MalwareRemsec

Remsec contains a keylogger component.

T1056.001
Keylogging
MalwareSykipot

Sykipot contains keylogging functionality to steal passwords.

T1056.001
Keylogging
MalwareExplosive

Explosive has leveraged its keylogging capabilities to gain access to administrator accounts on target servers.

T1056.001
Keylogging
MalwareRover

Rover has keylogging functionality.

T1056.001
Keylogging
MalwarePeppy

Peppy can log keystrokes on compromised hosts.

T1056.001
Keylogging
MalwareCuba

Cuba logs keystrokes via polling by using GetKeyState and VkKeyScan functions.

T1056.001
Keylogging
MalwareClambling

Clambling can capture keystrokes on a compromised host.

T1056.001
Keylogging
MalwareDarkGate

DarkGate will spawn a thread on execution to capture all keyboard events and write them to a predefined log file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.