ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1056.001
Keylogging
GroupOilRig

OilRig has employed keyloggers including KEYPUNCH and LONGWATCH.

T1056.001
Keylogging
GroupKe3chang

Ke3chang has used keyloggers.

T1056.001
Keylogging
GroupGroup5

Malware used by Group5 is capable of capturing keystrokes.

T1056.001
Keylogging
GroupDarkhotel

Darkhotel has used a keylogger.

T1056.001
Keylogging
GroupAPT28

APT28 has used tools to perform keylogging.

T1056.001
Keylogging
GroupAPT42

APT42 has used custom malware to log keystrokes.

T1056.001
Keylogging
GroupAPT5

APT5 has used malware with keylogging capabilities to monitor the communications of targeted entities.

T1056.001
Keylogging
GroupTonto Team

Tonto Team has used keylogging tools in their operations.

T1056.001
Keylogging
GroupLazarus Group

Lazarus Group malware KiloAlfa contains keylogging functionality.

T1056.001
Keylogging
GroupFIN4

FIN4 has captured credentials via fake Outlook Web App (OWA) login pages and has also used a .NET based keylogger.

T1056.001
Keylogging
GroupSowbug

Sowbug has used keylogging tools.

T1056.001
Keylogging
GroupHEXANE

HEXANE has used a PowerShell-based keylogger named `kl.ps1`.

T1056.001
Keylogging
GroupPLATINUM

PLATINUM has used several different keyloggers.

T1056.001
Keylogging
GroupMagic Hound

Magic Hound malware is capable of keylogging.

T1056.001
Keylogging
GroupAjax Security Team

Ajax Security Team has used CWoolger and MPK, custom-developed malware, which recorded all keystrokes on an infected system.

T1056.001
Keylogging
GroupThreat Group-3390

Threat Group-3390 actors installed a credential logger on Microsoft Exchange servers. Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes.

T1056.001
Keylogging
GroupFIN13

FIN13 has logged the keystrokes of victims to escalate privileges.

T1056.001
Keylogging
MalwareRCSession

RCSession has the ability to capture keystrokes on a compromised host.

T1056.001
Keylogging
Malwareyty

yty uses a keylogger plugin to gather keystrokes.

T1056.001
Keylogging
MalwareDOGCALL

DOGCALL is capable of logging keystrokes.

T1056.001
Keylogging
MalwarePAKLOG

PAKLOG has captured keystrokes using Windows API.

T1056.001
Keylogging
MalwareZeus Panda

Zeus Panda can perform keylogging on the victim’s machine by hooking the functions TranslateMessage and WM_KEYDOWN.

T1056.001
Keylogging
MalwareMatryoshka

Matryoshka is capable of keylogging.

T1056.001
Keylogging
MalwareInvisibleFerret

InvisibleFerret has conducted keylogging using the Python project “pyWinHook” and "Pyhook". InvisibleFerret has also captured keylogging thread checks for changes in an active window and key presses.

T1056.001
Keylogging
MalwareTONESHELL

TONESHELL has capabilities to conduct keylogging.

T1056.001
Keylogging
MalwareKasidet

Kasidet has the ability to initiate keylogging.

T1056.001
Keylogging
MalwareAppleSeed

AppleSeed can use GetKeyState and GetKeyboardState to capture keystrokes on the victim’s machine.

T1056.001
Keylogging
MalwareNETWIRE

NETWIRE can perform keylogging.

T1056.001
Keylogging
MalwareBOOKWORM

BOOKWORM has used its KBLogger.dll module to capture keystrokes and stored them in a folder.

T1056.001
Keylogging
MalwareCosmicDuke

CosmicDuke uses a keylogger.

T1056.001
Keylogging
MalwareEvilGrab

EvilGrab has the capability to capture keystrokes.

T1056.001
Keylogging
MalwareSslMM

SslMM creates a new thread implementing a keylogging facility using Windows Keyboard Accelerators.

T1056.001
Keylogging
MalwareGreyEnergy

GreyEnergy has a module to harvest pressed keystrokes.

T1056.001
Keylogging
MalwareCrimson

Crimson can use a module to perform keylogging on compromised hosts.

T1056.001
Keylogging
MalwareDUSTTRAP

DUSTTRAP can perform keylogging operations.

T1056.001
Keylogging
MalwareMachete

Machete logs keystrokes from the victim’s machine.

T1056.001
Keylogging
MalwarePowerLess

PowerLess can use a module to log keystrokes.

T1056.001
Keylogging
MalwarePrikormka

Prikormka contains a keylogger module that collects keystrokes and the titles of foreground windows.

T1056.001
Keylogging
MalwareHexEval Loader

HexEval Loader has utilized a cross-platform keylogger that has the capability to capture keystrokes on Windows, macOS and Linux systems.

T1056.001
Keylogging
MalwareFlawedAmmyy

FlawedAmmyy can collect keyboard events.

T1056.001
Keylogging
MalwareInvisiMole

InvisiMole can capture keystrokes on a compromised host.

T1056.001
Keylogging
MalwareOkrum

Okrum was seen using a keylogger tool to capture keystrokes.

T1056.001
Keylogging
MalwareRegin

Regin contains a keylogger.

T1056.001
Keylogging
MalwareMispadu

Mispadu can log keystrokes on the victim's machine.

T1056.001
Keylogging
MalwareFysbis

Fysbis can perform keylogging.

T1056.001
Keylogging
MalwareVERMIN

VERMIN collects keystrokes from the victim machine.

T1056.001
Keylogging
MalwareMarkiRAT

MarkiRAT can capture all keystrokes on a compromised host.

T1056.001
Keylogging
MalwareNavRAT

NavRAT logs the keystrokes on the targeted system.

T1056.001
Keylogging
MalwareDarkComet

DarkComet has a keylogging capability.

T1056.001
Keylogging
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has the ability to support keylogging.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.