Real-world descriptions of how a group, tool or campaign used a technique.
126 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareRCSession | RCSession has the ability to capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
Malwareyty | yty uses a keylogger plugin to gather keystrokes. |
| T1056.001 Keylogging |
MalwareDOGCALL | DOGCALL is capable of logging keystrokes. |
| T1056.001 Keylogging |
MalwarePAKLOG | PAKLOG has captured keystrokes using Windows API. |
| T1056.001 Keylogging |
MalwareZeus Panda | Zeus Panda can perform keylogging on the victim’s machine by hooking the functions TranslateMessage and WM_KEYDOWN. |
| T1056.001 Keylogging |
MalwareMatryoshka | Matryoshka is capable of keylogging. |
| T1056.001 Keylogging |
MalwareInvisibleFerret | InvisibleFerret has conducted keylogging using the Python project “pyWinHook” and "Pyhook". InvisibleFerret has also captured keylogging thread checks for changes in an active window and key presses. |
| T1056.001 Keylogging |
MalwareTONESHELL | TONESHELL has capabilities to conduct keylogging. |
| T1056.001 Keylogging |
MalwareKasidet | Kasidet has the ability to initiate keylogging. |
| T1056.001 Keylogging |
MalwareAppleSeed | AppleSeed can use |
| T1056.001 Keylogging |
MalwareNETWIRE | NETWIRE can perform keylogging. |
| T1056.001 Keylogging |
MalwareBOOKWORM | BOOKWORM has used its KBLogger.dll module to capture keystrokes and stored them in a folder. |
| T1056.001 Keylogging |
MalwareCosmicDuke | CosmicDuke uses a keylogger. |
| T1056.001 Keylogging |
MalwareEvilGrab | EvilGrab has the capability to capture keystrokes. |
| T1056.001 Keylogging |
MalwareSslMM | SslMM creates a new thread implementing a keylogging facility using Windows Keyboard Accelerators. |
| T1056.001 Keylogging |
MalwareGreyEnergy | GreyEnergy has a module to harvest pressed keystrokes. |
| T1056.001 Keylogging |
MalwareCrimson | Crimson can use a module to perform keylogging on compromised hosts. |
| T1056.001 Keylogging |
MalwareDUSTTRAP | DUSTTRAP can perform keylogging operations. |
| T1056.001 Keylogging |
MalwareMachete | Machete logs keystrokes from the victim’s machine. |
| T1056.001 Keylogging |
MalwarePowerLess | PowerLess can use a module to log keystrokes. |
| T1056.001 Keylogging |
MalwarePrikormka | Prikormka contains a keylogger module that collects keystrokes and the titles of foreground windows. |
| T1056.001 Keylogging |
MalwareHexEval Loader | HexEval Loader has utilized a cross-platform keylogger that has the capability to capture keystrokes on Windows, macOS and Linux systems. |
| T1056.001 Keylogging |
MalwareFlawedAmmyy | FlawedAmmyy can collect keyboard events. |
| T1056.001 Keylogging |
MalwareInvisiMole | InvisiMole can capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwareOkrum | Okrum was seen using a keylogger tool to capture keystrokes. |
| T1056.001 Keylogging |
MalwareRegin | Regin contains a keylogger. |
| T1056.001 Keylogging |
MalwareMispadu | Mispadu can log keystrokes on the victim's machine. |
| T1056.001 Keylogging |
MalwareFysbis | Fysbis can perform keylogging. |
| T1056.001 Keylogging |
MalwareVERMIN | VERMIN collects keystrokes from the victim machine. |
| T1056.001 Keylogging |
MalwareMarkiRAT | MarkiRAT can capture all keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwareNavRAT | NavRAT logs the keystrokes on the targeted system. |
| T1056.001 Keylogging |
MalwareDarkComet | DarkComet has a keylogging capability. |
| T1056.001 Keylogging |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to support keylogging. |
| T1056.001 Keylogging |
MalwareBlackEnergy | BlackEnergy has run a keylogger plug-in on a victim. |
| T1056.001 Keylogging |
MalwareXAgentOSX | XAgentOSX contains keylogging functionality that will monitor for active application windows and write them to the log, it can handle special characters, and it will buffer by default 50 characters before sending them out over the C2 infrastructure. |
| T1056.001 Keylogging |
MalwareKeyBoy | KeyBoy installs a keylogger for intercepting credentials and keystrokes. |
| T1056.001 Keylogging |
MalwareDarkTortilla | DarkTortilla can download a keylogging module. |
| T1056.001 Keylogging |
MalwareROKRAT | ROKRAT can use `SetWindowsHookEx` and `GetKeyNameText` to capture keystrokes. |
| T1056.001 Keylogging |
MalwareRunningRAT | RunningRAT captures keystrokes and sends them back to the C2 server. |
| T1056.001 Keylogging |
MalwareDarkWatchman | DarkWatchman can track key presses with a keylogger module. |
| T1056.001 Keylogging |
MalwarePlugX | PlugX has a module for capturing keystrokes per process including window titles. |
| T1056.001 Keylogging |
MalwareDustySky | DustySky contains a keylogger. |
| T1056.001 Keylogging |
MalwareRemsec | Remsec contains a keylogger component. |
| T1056.001 Keylogging |
MalwareSykipot | Sykipot contains keylogging functionality to steal passwords. |
| T1056.001 Keylogging |
MalwareExplosive | Explosive has leveraged its keylogging capabilities to gain access to administrator accounts on target servers. |
| T1056.001 Keylogging |
MalwareRover | Rover has keylogging functionality. |
| T1056.001 Keylogging |
MalwarePeppy | Peppy can log keystrokes on compromised hosts. |
| T1056.001 Keylogging |
MalwareCuba | Cuba logs keystrokes via polling by using |
| T1056.001 Keylogging |
MalwareClambling | Clambling can capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwareDarkGate | DarkGate will spawn a thread on execution to capture all keyboard events and write them to a predefined log file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.