Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.002 GUI Input Capture |
MalwareiKitten | iKitten prompts the user for their credentials. |
| T1056.002 GUI Input Capture |
MalwareCuckoo Stealer | Cuckoo Stealer has captured passwords by prompting victims with a “macOS needs to access System Settings” GUI window. |
| T1056.002 GUI Input Capture |
MalwareKeydnap | Keydnap prompts the users for credentials. |
| T1056.002 GUI Input Capture |
MalwareMispadu | Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1056.002 GUI Input Capture |
MalwareMuddyViper | MuddyViper has displayed a fake Windows Security dialog to gather credentials. |
| T1056.002 GUI Input Capture |
MalwareBundlore | Bundlore prompts the user for their credentials. |
| T1056.002 GUI Input Capture |
MalwareLP-Notes | LP-Notes has displayed a fake Windows Security dialog box to prompt for Windows credentials. |
| T1056.002 GUI Input Capture |
MalwareMetamorfo | Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims. |
| T1056.002 GUI Input Capture |
MalwareCalisto | Calisto presents an input prompt asking for the user's login and password. |
| T1056.002 GUI Input Capture |
MalwareProton | Proton prompts users for their credentials. |
| T1056.002 GUI Input Capture |
MalwareXCSSET | XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process |
| T1056.002 GUI Input Capture |
MalwareDok | Dok prompts the user for credentials. |
| T1056.002 GUI Input Capture |
ToolSILENTTRINITY | SILENTTRINITY's `credphisher.py` module can prompt a current user for their credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.