Real-world descriptions of how a group, tool or campaign used a technique.
26 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
GroupAPT38 | APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine. |
| T1056.001 Keylogging |
GroupAPT3 | APT3 has used a keylogging tool that records keystrokes in encrypted files. |
| T1056.001 Keylogging |
GroupKimsuky | Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory. |
| T1056.001 Keylogging |
GroupVolt Typhoon | Volt Typhoon has created and accessed a file named rult3uil.log on compromised domain controllers to capture keypresses and command execution. |
| T1056.001 Keylogging |
GroupAPT41 | APT41 used a keylogger called GEARSHIFT on a target system. |
| T1056.001 Keylogging |
GroupmenuPass | menuPass has used key loggers to steal usernames and passwords. |
| T1056.001 Keylogging |
GroupAPT32 | APT32 has abused the PasswordChangeNotify to monitor for and capture account password changes. |
| T1056.001 Keylogging |
GroupSandworm Team | Sandworm Team has used a keylogger to capture keystrokes by using the SetWindowsHookEx function. |
| T1056.001 Keylogging |
GroupAPT39 | APT39 has used tools for capturing keystrokes. |
| T1056.001 Keylogging |
GroupOilRig | OilRig has employed keyloggers including KEYPUNCH and LONGWATCH. |
| T1056.001 Keylogging |
GroupKe3chang | Ke3chang has used keyloggers. |
| T1056.001 Keylogging |
GroupGroup5 | Malware used by Group5 is capable of capturing keystrokes. |
| T1056.001 Keylogging |
GroupDarkhotel | Darkhotel has used a keylogger. |
| T1056.001 Keylogging |
GroupAPT28 | APT28 has used tools to perform keylogging. |
| T1056.001 Keylogging |
GroupAPT42 | APT42 has used custom malware to log keystrokes. |
| T1056.001 Keylogging |
GroupAPT5 | APT5 has used malware with keylogging capabilities to monitor the communications of targeted entities. |
| T1056.001 Keylogging |
GroupTonto Team | Tonto Team has used keylogging tools in their operations. |
| T1056.001 Keylogging |
GroupLazarus Group | Lazarus Group malware KiloAlfa contains keylogging functionality. |
| T1056.001 Keylogging |
GroupFIN4 | FIN4 has captured credentials via fake Outlook Web App (OWA) login pages and has also used a .NET based keylogger. |
| T1056.001 Keylogging |
GroupSowbug | Sowbug has used keylogging tools. |
| T1056.001 Keylogging |
GroupHEXANE | HEXANE has used a PowerShell-based keylogger named `kl.ps1`. |
| T1056.001 Keylogging |
GroupPLATINUM | PLATINUM has used several different keyloggers. |
| T1056.001 Keylogging |
GroupMagic Hound | Magic Hound malware is capable of keylogging. |
| T1056.001 Keylogging |
GroupAjax Security Team | Ajax Security Team has used CWoolger and MPK, custom-developed malware, which recorded all keystrokes on an infected system. |
| T1056.001 Keylogging |
GroupThreat Group-3390 | Threat Group-3390 actors installed a credential logger on Microsoft Exchange servers. Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes. |
| T1056.001 Keylogging |
GroupFIN13 | FIN13 has logged the keystrokes of victims to escalate privileges. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.