Real-world descriptions of how a group, tool or campaign used a technique.
126 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareThiefQuest | ThiefQuest uses the |
| T1056.001 Keylogging |
MalwareCarbanak | Carbanak logs key strokes for configured processes and sends them back to the C2 server. |
| T1056.001 Keylogging |
MalwareLODEINFO | LODEINFO can capture keystrokes on targeted systems. |
| T1056.001 Keylogging |
MalwareSMOKEDHAM | SMOKEDHAM can continuously capture keystrokes. |
| T1056.001 Keylogging |
MalwareMetamorfo | Metamorfo has a command to launch a keylogger and capture keystrokes on the victim’s machine. |
| T1056.001 Keylogging |
MalwareTrojan.Karagany | Trojan.Karagany can capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwareBandook | Bandook contains keylogging capabilities. |
| T1056.001 Keylogging |
MalwareKONNI | KONNI has the capability to perform keylogging. |
| T1056.001 Keylogging |
Malwaregh0st RAT | gh0st RAT has a keylogger. |
| T1056.001 Keylogging |
MalwareKGH_SPY | KGH_SPY can perform keylogging by polling the |
| T1056.001 Keylogging |
MalwareMicropsia | Micropsia has keylogging capabilities. |
| T1056.001 Keylogging |
MalwareCatchamas | Catchamas collects keystrokes from the victim’s machine. |
| T1056.001 Keylogging |
MalwareAttor | One of Attor's plugins can collect user credentials via capturing keystrokes and can capture keystrokes pressed within the window of the injected process. |
| T1056.001 Keylogging |
MalwareNightClub | NightClub can use a plugin for keylogging. |
| T1056.001 Keylogging |
MalwareRTM | RTM can record keystrokes from both the keyboard and virtual keyboard. |
| T1056.001 Keylogging |
MalwareDerusbi | Derusbi is capable of logging keystrokes. |
| T1056.001 Keylogging |
MalwareGrandoreiro | Grandoreiro can log keystrokes on the victim's machine. |
| T1056.001 Keylogging |
MalwareBadPatch | BadPatch has a keylogging capability. |
| T1056.001 Keylogging |
MalwareXLoader | XLoader can capture keystrokes from the victim machine. |
| T1056.001 Keylogging |
MalwareMoonWind | MoonWind has a keylogger. |
| T1056.001 Keylogging |
MalwareCorKLOG | CorKLOG has captured keystrokes. |
| T1056.001 Keylogging |
MalwareMgBot | MgBot includes keylogger payloads focused on the QQ chat application. |
| T1056.001 Keylogging |
MalwareOwaAuth | OwaAuth captures and DES-encrypts credentials before writing the username and password to a log file, |
| T1056.001 Keylogging |
MalwareCadelspy | Cadelspy has the ability to log keystrokes on the compromised host. |
| T1056.001 Keylogging |
MalwareCobalt Strike | Cobalt Strike can track key presses with a keylogger module. |
| T1056.001 Keylogging |
MalwareCobian RAT | Cobian RAT has a feature to perform keylogging on the victim’s machine. |
| T1056.001 Keylogging |
MalwareUnknown Logger | Unknown Logger is capable of recording keystrokes. |
| T1056.001 Keylogging |
MalwareKivars | Kivars has the ability to initiate keylogging on the infected host. |
| T1056.001 Keylogging |
MalwarePoisonIvy | PoisonIvy contains a keylogger. |
| T1056.001 Keylogging |
MalwareNanoCore | NanoCore can perform keylogging on the victim’s machine. |
| T1056.001 Keylogging |
MalwareTajMahal | TajMahal has the ability to capture keystrokes on an infected host. |
| T1056.001 Keylogging |
MalwareDaserf | Daserf can log keystrokes. |
| T1056.001 Keylogging |
MalwareCardinal RAT | Cardinal RAT can log keystrokes. |
| T1056.001 Keylogging |
MalwareBISCUIT | BISCUIT can capture keystrokes. |
| T1056.001 Keylogging |
MalwareFakeM | FakeM contains a keylogger module. |
| T1056.001 Keylogging |
MalwareRevenge RAT | Revenge RAT has a plugin for keylogging. |
| T1056.001 Keylogging |
MalwareMacMa | MacMa can use Core Graphics Event Taps to intercept user keystrokes from any text input field and saves them to text files. Text input fields include Spotlight, Finder, Safari, Mail, Messages, and other apps that have text fields for passwords. |
| T1056.001 Keylogging |
MalwareFunnyDream | The FunnyDream Keyrecord component can capture keystrokes. |
| T1056.001 Keylogging |
MalwareTinyZBot | TinyZBot contains keylogger functionality. |
| T1056.001 Keylogging |
MalwareProton | Proton uses a keylogger to capture keystrokes. |
| T1056.001 Keylogging |
MalwareNetTraveler | NetTraveler contains a keylogger. |
| T1056.001 Keylogging |
MalwareLokibot | Lokibot has the ability to capture input on the compromised host via keylogging. |
| T1056.001 Keylogging |
MalwarePoetRAT | PoetRAT has used a Python tool named klog.exe for keylogging. |
| T1056.001 Keylogging |
MalwareCHOPSTICK | CHOPSTICK is capable of performing keylogging. |
| T1056.001 Keylogging |
MalwareZxShell | ZxShell has a feature to capture a remote computer's keystrokes using a keylogger. |
| T1056.001 Keylogging |
MalwareBabyShark | BabyShark has a PowerShell-based remote administration ability that can implement a PowerShell or C# based keylogger. |
| T1056.001 Keylogging |
MalwarenjRAT | njRAT is capable of logging keystrokes. |
| T1056.001 Keylogging |
MalwareJPIN | JPIN contains a custom keylogger. |
| T1056.001 Keylogging |
MalwaremetaMain | metaMain has the ability to log keyboard events. |
| T1056.001 Keylogging |
MalwareHTTPBrowser | HTTPBrowser is capable of capturing keystrokes on victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.