ATT&CKReferencesRapid7 KeyBoy Jun 2013

Rapid7 KeyBoy Jun 2013

Guarnieri, C., Schloesser M. (2013, June 7). KeyBoy, Targeted Attacks against Vietnam and India. Retrieved June 14, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareKeyBoy

KeyBoy installs a keylogger for intercepting credentials and keystrokes.

T1059.003
Windows Command Shell
MalwareKeyBoy

KeyBoy can launch interactive shells for communicating with the victim machine.

T1082
System Information Discovery
MalwareKeyBoy

KeyBoy can gather extended system information, such as information about the operating system and memory.

T1105
Ingress Tool Transfer
MalwareKeyBoy

KeyBoy has a download and upload functionality.

T1543.003
Windows Service
MalwareKeyBoy

KeyBoy installs a service pointing to a malicious DLL dropped to disk.

T1555.003
Credentials from Web Browsers
MalwareKeyBoy

KeyBoy attempts to collect passwords from browsers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.