Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
GroupOilRig | OilRig has employed keyloggers including KEYPUNCH and LONGWATCH. |
| T1056.001 Keylogging |
GroupKe3chang | Ke3chang has used keyloggers. |
| T1056.001 Keylogging |
GroupGroup5 | Malware used by Group5 is capable of capturing keystrokes. |
| T1056.001 Keylogging |
GroupDarkhotel | Darkhotel has used a keylogger. |
| T1056.001 Keylogging |
GroupAPT28 | APT28 has used tools to perform keylogging. |
| T1056.001 Keylogging |
GroupAPT42 | APT42 has used custom malware to log keystrokes. |
| T1056.001 Keylogging |
GroupAPT5 | APT5 has used malware with keylogging capabilities to monitor the communications of targeted entities. |
| T1056.001 Keylogging |
GroupTonto Team | Tonto Team has used keylogging tools in their operations. |
| T1056.001 Keylogging |
GroupLazarus Group | Lazarus Group malware KiloAlfa contains keylogging functionality. |
| T1056.001 Keylogging |
GroupFIN4 | FIN4 has captured credentials via fake Outlook Web App (OWA) login pages and has also used a .NET based keylogger. |
| T1056.001 Keylogging |
GroupSowbug | Sowbug has used keylogging tools. |
| T1056.001 Keylogging |
GroupHEXANE | HEXANE has used a PowerShell-based keylogger named `kl.ps1`. |
| T1056.001 Keylogging |
GroupPLATINUM | PLATINUM has used several different keyloggers. |
| T1056.001 Keylogging |
GroupMagic Hound | Magic Hound malware is capable of keylogging. |
| T1056.001 Keylogging |
GroupAjax Security Team | Ajax Security Team has used CWoolger and MPK, custom-developed malware, which recorded all keystrokes on an infected system. |
| T1056.001 Keylogging |
GroupThreat Group-3390 | Threat Group-3390 actors installed a credential logger on Microsoft Exchange servers. Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes. |
| T1056.001 Keylogging |
GroupFIN13 | FIN13 has logged the keystrokes of victims to escalate privileges. |
| T1056.001 Keylogging |
MalwareRCSession | RCSession has the ability to capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
Malwareyty | yty uses a keylogger plugin to gather keystrokes. |
| T1056.001 Keylogging |
MalwareDOGCALL | DOGCALL is capable of logging keystrokes. |
| T1056.001 Keylogging |
MalwarePAKLOG | PAKLOG has captured keystrokes using Windows API. |
| T1056.001 Keylogging |
MalwareZeus Panda | Zeus Panda can perform keylogging on the victim’s machine by hooking the functions TranslateMessage and WM_KEYDOWN. |
| T1056.001 Keylogging |
MalwareMatryoshka | Matryoshka is capable of keylogging. |
| T1056.001 Keylogging |
MalwareInvisibleFerret | InvisibleFerret has conducted keylogging using the Python project “pyWinHook” and "Pyhook". InvisibleFerret has also captured keylogging thread checks for changes in an active window and key presses. |
| T1056.001 Keylogging |
MalwareTONESHELL | TONESHELL has capabilities to conduct keylogging. |
| T1056.001 Keylogging |
MalwareKasidet | Kasidet has the ability to initiate keylogging. |
| T1056.001 Keylogging |
MalwareAppleSeed | AppleSeed can use |
| T1056.001 Keylogging |
MalwareNETWIRE | NETWIRE can perform keylogging. |
| T1056.001 Keylogging |
MalwareBOOKWORM | BOOKWORM has used its KBLogger.dll module to capture keystrokes and stored them in a folder. |
| T1056.001 Keylogging |
MalwareCosmicDuke | CosmicDuke uses a keylogger. |
| T1056.001 Keylogging |
MalwareEvilGrab | EvilGrab has the capability to capture keystrokes. |
| T1056.001 Keylogging |
MalwareSslMM | SslMM creates a new thread implementing a keylogging facility using Windows Keyboard Accelerators. |
| T1056.001 Keylogging |
MalwareGreyEnergy | GreyEnergy has a module to harvest pressed keystrokes. |
| T1056.001 Keylogging |
MalwareCrimson | Crimson can use a module to perform keylogging on compromised hosts. |
| T1056.001 Keylogging |
MalwareDUSTTRAP | DUSTTRAP can perform keylogging operations. |
| T1056.001 Keylogging |
MalwareMachete | Machete logs keystrokes from the victim’s machine. |
| T1056.001 Keylogging |
MalwarePowerLess | PowerLess can use a module to log keystrokes. |
| T1056.001 Keylogging |
MalwarePrikormka | Prikormka contains a keylogger module that collects keystrokes and the titles of foreground windows. |
| T1056.001 Keylogging |
MalwareHexEval Loader | HexEval Loader has utilized a cross-platform keylogger that has the capability to capture keystrokes on Windows, macOS and Linux systems. |
| T1056.001 Keylogging |
MalwareFlawedAmmyy | FlawedAmmyy can collect keyboard events. |
| T1056.001 Keylogging |
MalwareInvisiMole | InvisiMole can capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwareOkrum | Okrum was seen using a keylogger tool to capture keystrokes. |
| T1056.001 Keylogging |
MalwareRegin | Regin contains a keylogger. |
| T1056.001 Keylogging |
MalwareMispadu | Mispadu can log keystrokes on the victim's machine. |
| T1056.001 Keylogging |
MalwareFysbis | Fysbis can perform keylogging. |
| T1056.001 Keylogging |
MalwareVERMIN | VERMIN collects keystrokes from the victim machine. |
| T1056.001 Keylogging |
MalwareMarkiRAT | MarkiRAT can capture all keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwareNavRAT | NavRAT logs the keystrokes on the targeted system. |
| T1056.001 Keylogging |
MalwareDarkComet | DarkComet has a keylogging capability. |
| T1056.001 Keylogging |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to support keylogging. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.