Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareBISCUIT | BISCUIT can capture keystrokes. |
| T1056.001 Keylogging |
MalwareFakeM | FakeM contains a keylogger module. |
| T1056.001 Keylogging |
MalwareRevenge RAT | Revenge RAT has a plugin for keylogging. |
| T1056.001 Keylogging |
MalwareMacMa | MacMa can use Core Graphics Event Taps to intercept user keystrokes from any text input field and saves them to text files. Text input fields include Spotlight, Finder, Safari, Mail, Messages, and other apps that have text fields for passwords. |
| T1056.001 Keylogging |
MalwareFunnyDream | The FunnyDream Keyrecord component can capture keystrokes. |
| T1056.001 Keylogging |
MalwareTinyZBot | TinyZBot contains keylogger functionality. |
| T1056.001 Keylogging |
MalwareProton | Proton uses a keylogger to capture keystrokes. |
| T1056.001 Keylogging |
MalwareNetTraveler | NetTraveler contains a keylogger. |
| T1056.001 Keylogging |
MalwareLokibot | Lokibot has the ability to capture input on the compromised host via keylogging. |
| T1056.001 Keylogging |
MalwarePoetRAT | PoetRAT has used a Python tool named klog.exe for keylogging. |
| T1056.001 Keylogging |
MalwareCHOPSTICK | CHOPSTICK is capable of performing keylogging. |
| T1056.001 Keylogging |
MalwareZxShell | ZxShell has a feature to capture a remote computer's keystrokes using a keylogger. |
| T1056.001 Keylogging |
MalwareBabyShark | BabyShark has a PowerShell-based remote administration ability that can implement a PowerShell or C# based keylogger. |
| T1056.001 Keylogging |
MalwarenjRAT | njRAT is capable of logging keystrokes. |
| T1056.001 Keylogging |
MalwareJPIN | JPIN contains a custom keylogger. |
| T1056.001 Keylogging |
MalwaremetaMain | metaMain has the ability to log keyboard events. |
| T1056.001 Keylogging |
MalwareHTTPBrowser | HTTPBrowser is capable of capturing keystrokes on victims. |
| T1056.001 Keylogging |
MalwareAgent Tesla | Agent Tesla can log keystrokes on the victim’s machine. |
| T1056.001 Keylogging |
MalwareECCENTRICBANDWAGON | ECCENTRICBANDWAGON can capture and store keystrokes. |
| T1056.001 Keylogging |
MalwareBADNEWS | When it first starts, BADNEWS spawns a new thread to log keystrokes. |
| T1056.001 Keylogging |
MalwareDRYHOOK | DRYHOOK has captured user credentials and passwords in plaintext and has encrypted them in a stored file on the network device. |
| T1056.001 Keylogging |
MalwareRemexi | Remexi gathers and exfiltrates keystrokes from the machine. |
| T1056.001 Keylogging |
MalwareAstaroth | Astaroth logs keystrokes from the victim's machine. |
| T1056.001 Keylogging |
MalwareQakBot | QakBot can capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwarejRAT | jRAT has the capability to log keystrokes from the victim’s machine, both offline and online. |
| T1056.001 Keylogging |
MalwareHelminth | The executable version of Helminth has a module to log keystrokes. |
| T1056.001 Keylogging |
MalwareMacSpy | MacSpy captures keystrokes. |
| T1056.001 Keylogging |
MalwareDtrack | Dtrack’s dropper contains a keylogging executable. |
| T1056.001 Keylogging |
MalwareADVSTORESHELL | ADVSTORESHELL can perform keylogging. |
| T1056.001 Keylogging |
MalwareWarzoneRAT | WarzoneRAT has the capability to install a live and offline keylogger, including through the use of the `GetAsyncKeyState` Windows API. |
| T1056.001 Keylogging |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has a keylogging capability. |
| T1056.001 Keylogging |
ToolSILENTTRINITY | SILENTTRINITY has a keylogging capability. |
| T1056.001 Keylogging |
ToolPowerSploit | PowerSploit's |
| T1056.001 Keylogging |
ToolDCRAT | DCRAT can log keystrokes on targeted systems. |
| T1056.001 Keylogging |
ToolEmpire | Empire includes keylogging capabilities for Windows, Linux, and macOS systems. |
| T1056.001 Keylogging |
ToolPcShare | PcShare has the ability to capture keystrokes. |
| T1056.001 Keylogging |
ToolPoshC2 | PoshC2 has modules for keystroke logging and capturing credentials from spoofed Outlook authentication messages. |
| T1056.001 Keylogging |
ToolAsyncRAT | AsyncRAT can capture keystrokes on the victim’s machine. |
| T1056.001 Keylogging |
ToolRemcos | Remcos has a command for keylogging. |
| T1056.001 Keylogging |
ToolImminent Monitor | Imminent Monitor has a keylogging module. |
| T1056.001 Keylogging |
ToolPupy | Pupy uses a keylogger to capture keystrokes it then sends back to the server after it is stopped. |
| T1056.001 Keylogging |
ToolQuasarRAT | QuasarRAT has a built-in keylogger. |
| T1056.001 Keylogging |
MalwareDuqu | Duqu can track key presses with a keylogger module. |
| T1056.002 GUI Input Capture |
GroupRedCurl | RedCurl prompts the user for credentials through a Microsoft Outlook pop-up. |
| T1056.002 GUI Input Capture |
GroupFIN4 | FIN4 has presented victims with spoofed Windows Authentication prompts to collect their credentials. |
| T1056.002 GUI Input Capture |
MalwareiKitten | iKitten prompts the user for their credentials. |
| T1056.002 GUI Input Capture |
MalwareCuckoo Stealer | Cuckoo Stealer has captured passwords by prompting victims with a “macOS needs to access System Settings” GUI window. |
| T1056.002 GUI Input Capture |
MalwareKeydnap | Keydnap prompts the users for credentials. |
| T1056.002 GUI Input Capture |
MalwareMispadu | Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1056.002 GUI Input Capture |
MalwareMuddyViper | MuddyViper has displayed a fake Windows Security dialog to gather credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.