ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1056.002×

13 examples

TechniqueUsed byProcedure example
T1056.002
GUI Input Capture
MalwareiKitten

iKitten prompts the user for their credentials.

T1056.002
GUI Input Capture
MalwareCuckoo Stealer

Cuckoo Stealer has captured passwords by prompting victims with a “macOS needs to access System Settings” GUI window.

T1056.002
GUI Input Capture
MalwareKeydnap

Keydnap prompts the users for credentials.

T1056.002
GUI Input Capture
MalwareMispadu

Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1056.002
GUI Input Capture
MalwareMuddyViper

MuddyViper has displayed a fake Windows Security dialog to gather credentials.

T1056.002
GUI Input Capture
MalwareBundlore

Bundlore prompts the user for their credentials.

T1056.002
GUI Input Capture
MalwareLP-Notes

LP-Notes has displayed a fake Windows Security dialog box to prompt for Windows credentials.

T1056.002
GUI Input Capture
MalwareMetamorfo

Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims.

T1056.002
GUI Input Capture
MalwareCalisto

Calisto presents an input prompt asking for the user's login and password.

T1056.002
GUI Input Capture
MalwareProton

Proton prompts users for their credentials.

T1056.002
GUI Input Capture
MalwareXCSSET

XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process /Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment.

T1056.002
GUI Input Capture
MalwareDok

Dok prompts the user for credentials.

T1056.002
GUI Input Capture
ToolSILENTTRINITY

SILENTTRINITY's `credphisher.py` module can prompt a current user for their credentials.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.