Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056 Input Capture |
MalwareChaes | Chaes has a module to perform any API hooking it desires. |
| T1056 Input Capture |
MalwareKobalos | Kobalos has used a compromised SSH client to capture the hostname, port, username and password used to establish an SSH connection from the compromised host. |
| T1056 Input Capture |
MalwaremetaMain | metaMain can log mouse events. |
| T1056 Input Capture |
ToolNPPSPY | NPPSPY captures user input into the Winlogon process by redirecting RPC traffic from legitimate listening DLLs within the operating system to a newly registered malicious item that allows for recording logon information in cleartext. |
| T1056.001 Keylogging |
MalwareRCSession | RCSession has the ability to capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
Malwareyty | yty uses a keylogger plugin to gather keystrokes. |
| T1056.001 Keylogging |
MalwareDOGCALL | DOGCALL is capable of logging keystrokes. |
| T1056.001 Keylogging |
MalwarePAKLOG | PAKLOG has captured keystrokes using Windows API. |
| T1056.001 Keylogging |
MalwareZeus Panda | Zeus Panda can perform keylogging on the victim’s machine by hooking the functions TranslateMessage and WM_KEYDOWN. |
| T1056.001 Keylogging |
MalwareMatryoshka | Matryoshka is capable of keylogging. |
| T1056.001 Keylogging |
MalwareInvisibleFerret | InvisibleFerret has conducted keylogging using the Python project “pyWinHook” and "Pyhook". InvisibleFerret has also captured keylogging thread checks for changes in an active window and key presses. |
| T1056.001 Keylogging |
MalwareTONESHELL | TONESHELL has capabilities to conduct keylogging. |
| T1056.001 Keylogging |
MalwareKasidet | Kasidet has the ability to initiate keylogging. |
| T1056.001 Keylogging |
MalwareAppleSeed | AppleSeed can use |
| T1056.001 Keylogging |
MalwareNETWIRE | NETWIRE can perform keylogging. |
| T1056.001 Keylogging |
MalwareBOOKWORM | BOOKWORM has used its KBLogger.dll module to capture keystrokes and stored them in a folder. |
| T1056.001 Keylogging |
MalwareCosmicDuke | CosmicDuke uses a keylogger. |
| T1056.001 Keylogging |
MalwareEvilGrab | EvilGrab has the capability to capture keystrokes. |
| T1056.001 Keylogging |
MalwareSslMM | SslMM creates a new thread implementing a keylogging facility using Windows Keyboard Accelerators. |
| T1056.001 Keylogging |
MalwareGreyEnergy | GreyEnergy has a module to harvest pressed keystrokes. |
| T1056.001 Keylogging |
MalwareCrimson | Crimson can use a module to perform keylogging on compromised hosts. |
| T1056.001 Keylogging |
MalwareDUSTTRAP | DUSTTRAP can perform keylogging operations. |
| T1056.001 Keylogging |
MalwareMachete | Machete logs keystrokes from the victim’s machine. |
| T1056.001 Keylogging |
MalwarePowerLess | PowerLess can use a module to log keystrokes. |
| T1056.001 Keylogging |
MalwarePrikormka | Prikormka contains a keylogger module that collects keystrokes and the titles of foreground windows. |
| T1056.001 Keylogging |
MalwareHexEval Loader | HexEval Loader has utilized a cross-platform keylogger that has the capability to capture keystrokes on Windows, macOS and Linux systems. |
| T1056.001 Keylogging |
MalwareFlawedAmmyy | FlawedAmmyy can collect keyboard events. |
| T1056.001 Keylogging |
MalwareInvisiMole | InvisiMole can capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwareOkrum | Okrum was seen using a keylogger tool to capture keystrokes. |
| T1056.001 Keylogging |
MalwareRegin | Regin contains a keylogger. |
| T1056.001 Keylogging |
MalwareMispadu | Mispadu can log keystrokes on the victim's machine. |
| T1056.001 Keylogging |
MalwareFysbis | Fysbis can perform keylogging. |
| T1056.001 Keylogging |
MalwareVERMIN | VERMIN collects keystrokes from the victim machine. |
| T1056.001 Keylogging |
MalwareMarkiRAT | MarkiRAT can capture all keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwareNavRAT | NavRAT logs the keystrokes on the targeted system. |
| T1056.001 Keylogging |
MalwareDarkComet | DarkComet has a keylogging capability. |
| T1056.001 Keylogging |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to support keylogging. |
| T1056.001 Keylogging |
MalwareBlackEnergy | BlackEnergy has run a keylogger plug-in on a victim. |
| T1056.001 Keylogging |
MalwareXAgentOSX | XAgentOSX contains keylogging functionality that will monitor for active application windows and write them to the log, it can handle special characters, and it will buffer by default 50 characters before sending them out over the C2 infrastructure. |
| T1056.001 Keylogging |
MalwareKeyBoy | KeyBoy installs a keylogger for intercepting credentials and keystrokes. |
| T1056.001 Keylogging |
MalwareDarkTortilla | DarkTortilla can download a keylogging module. |
| T1056.001 Keylogging |
MalwareROKRAT | ROKRAT can use `SetWindowsHookEx` and `GetKeyNameText` to capture keystrokes. |
| T1056.001 Keylogging |
MalwareRunningRAT | RunningRAT captures keystrokes and sends them back to the C2 server. |
| T1056.001 Keylogging |
MalwareDarkWatchman | DarkWatchman can track key presses with a keylogger module. |
| T1056.001 Keylogging |
MalwarePlugX | PlugX has a module for capturing keystrokes per process including window titles. |
| T1056.001 Keylogging |
MalwareDustySky | DustySky contains a keylogger. |
| T1056.001 Keylogging |
MalwareRemsec | Remsec contains a keylogger component. |
| T1056.001 Keylogging |
MalwareSykipot | Sykipot contains keylogging functionality to steal passwords. |
| T1056.001 Keylogging |
MalwareExplosive | Explosive has leveraged its keylogging capabilities to gain access to administrator accounts on target servers. |
| T1056.001 Keylogging |
MalwareRover | Rover has keylogging functionality. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.