ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1056.001×

26 examples

TechniqueUsed byProcedure example
T1056.001
Keylogging
GroupAPT38

APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine.

T1056.001
Keylogging
GroupAPT3

APT3 has used a keylogging tool that records keystrokes in encrypted files.

T1056.001
Keylogging
GroupKimsuky

Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory.

T1056.001
Keylogging
GroupVolt Typhoon

Volt Typhoon has created and accessed a file named rult3uil.log on compromised domain controllers to capture keypresses and command execution.

T1056.001
Keylogging
GroupAPT41

APT41 used a keylogger called GEARSHIFT on a target system.

T1056.001
Keylogging
GroupmenuPass

menuPass has used key loggers to steal usernames and passwords.

T1056.001
Keylogging
GroupAPT32

APT32 has abused the PasswordChangeNotify to monitor for and capture account password changes.

T1056.001
Keylogging
GroupSandworm Team

Sandworm Team has used a keylogger to capture keystrokes by using the SetWindowsHookEx function.

T1056.001
Keylogging
GroupAPT39

APT39 has used tools for capturing keystrokes.

T1056.001
Keylogging
GroupOilRig

OilRig has employed keyloggers including KEYPUNCH and LONGWATCH.

T1056.001
Keylogging
GroupKe3chang

Ke3chang has used keyloggers.

T1056.001
Keylogging
GroupGroup5

Malware used by Group5 is capable of capturing keystrokes.

T1056.001
Keylogging
GroupDarkhotel

Darkhotel has used a keylogger.

T1056.001
Keylogging
GroupAPT28

APT28 has used tools to perform keylogging.

T1056.001
Keylogging
GroupAPT42

APT42 has used custom malware to log keystrokes.

T1056.001
Keylogging
GroupAPT5

APT5 has used malware with keylogging capabilities to monitor the communications of targeted entities.

T1056.001
Keylogging
GroupTonto Team

Tonto Team has used keylogging tools in their operations.

T1056.001
Keylogging
GroupLazarus Group

Lazarus Group malware KiloAlfa contains keylogging functionality.

T1056.001
Keylogging
GroupFIN4

FIN4 has captured credentials via fake Outlook Web App (OWA) login pages and has also used a .NET based keylogger.

T1056.001
Keylogging
GroupSowbug

Sowbug has used keylogging tools.

T1056.001
Keylogging
GroupHEXANE

HEXANE has used a PowerShell-based keylogger named `kl.ps1`.

T1056.001
Keylogging
GroupPLATINUM

PLATINUM has used several different keyloggers.

T1056.001
Keylogging
GroupMagic Hound

Magic Hound malware is capable of keylogging.

T1056.001
Keylogging
GroupAjax Security Team

Ajax Security Team has used CWoolger and MPK, custom-developed malware, which recorded all keystrokes on an infected system.

T1056.001
Keylogging
GroupThreat Group-3390

Threat Group-3390 actors installed a credential logger on Microsoft Exchange servers. Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes.

T1056.001
Keylogging
GroupFIN13

FIN13 has logged the keystrokes of victims to escalate privileges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.