Sub-technique of T1056 Input Capture.View on attack.mitre.org
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.
Keylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes. Some methods include:
* Hooking API callbacks used for processing keystrokes. Unlike Credential API Hooking, this focuses solely on API functions intended for processing keystroke data.
* Reading raw keystroke data from the hardware buffer.
* Windows Registry modifications.
* Custom drivers.
* Modify System Image may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.
Rules on DetectionCode tagged with T1056.001.
| Rule | Level | Log source |
|---|---|---|
| Linux Keylogging with Pam.d | high | linux / NULL |
| Potential Keylogger Activity | medium | windows / ps_script |
| Powershell Keylogging | medium | windows / ps_script |
| Used by | Procedure example |
|---|---|
| GroupAjax Security Team | Ajax Security Team has used CWoolger and MPK, custom-developed malware, which recorded all keystrokes on an infected system. |
| GroupAPT28 | APT28 has used tools to perform keylogging. |
| GroupAPT3 | APT3 has used a keylogging tool that records keystrokes in encrypted files. |
| GroupAPT32 | APT32 has abused the PasswordChangeNotify to monitor for and capture account password changes. |
| GroupAPT38 | APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine. |
| GroupAPT39 | APT39 has used tools for capturing keystrokes. |
| GroupAPT41 | APT41 used a keylogger called GEARSHIFT on a target system. |
| GroupAPT42 | APT42 has used custom malware to log keystrokes. |
| Used by | Procedure example |
|---|---|
| MalwareADVSTORESHELL | ADVSTORESHELL can perform keylogging. |
| MalwareAgent Tesla | Agent Tesla can log keystrokes on the victim’s machine. |
| MalwareAppleSeed | AppleSeed can use |
| MalwareAstaroth | Astaroth logs keystrokes from the victim's machine. |
| ToolAsyncRAT | AsyncRAT can capture keystrokes on the victim’s machine. |
| MalwareAttor | One of Attor's plugins can collect user credentials via capturing keystrokes and can capture keystrokes pressed within the window of the injected process. |
| MalwareBabyShark | BabyShark has a PowerShell-based remote administration ability that can implement a PowerShell or C# based keylogger. |
| MalwareBADNEWS | When it first starts, BADNEWS spawns a new thread to log keystrokes. |
View all 126 software examples
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team gathered account credentials via a BlackEnergy keylogger plugin. |
| CampaignCutting Edge | During Cutting Edge, threat actors modified a JavaScript file on the Web SSL VPN component of Ivanti Connect Secure devices to keylog credentials. |
| CampaignOperation Wocao | During Operation Wocao, threat actors obtained the password for the victim's password manager via a custom keylogger. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.