Keylogging

T1056.001

Sub-technique of T1056 Input Capture.View on attack.mitre.org

About this technique

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.

Keylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes. Some methods include:

* Hooking API callbacks used for processing keystrokes. Unlike Credential API Hooking, this focuses solely on API functions intended for processing keystroke data.
* Reading raw keystroke data from the hardware buffer.
* Windows Registry modifications.
* Custom drivers.
* Modify System Image may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.

Detection rules3

Rules on DetectionCode tagged with T1056.001.

Sigma3

RuleLevelLog source
Linux Keylogging with Pam.dhighlinux / NULL
Potential Keylogger Activitymediumwindows / ps_script
Powershell Keyloggingmediumwindows / ps_script

Splunk0

No Splunk rules are mapped to this technique yet.

Groups26

Show 2 more

Software126

Show 102 more

Campaigns3

Procedure examples155

Groups26

Used byProcedure example
GroupAjax Security Team

Ajax Security Team has used CWoolger and MPK, custom-developed malware, which recorded all keystrokes on an infected system.

GroupAPT28

APT28 has used tools to perform keylogging.

GroupAPT3

APT3 has used a keylogging tool that records keystrokes in encrypted files.

GroupAPT32

APT32 has abused the PasswordChangeNotify to monitor for and capture account password changes.

GroupAPT38

APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine.

GroupAPT39

APT39 has used tools for capturing keystrokes.

GroupAPT41

APT41 used a keylogger called GEARSHIFT on a target system.

GroupAPT42

APT42 has used custom malware to log keystrokes.

View all 26 groups examples

Software126

Used byProcedure example
MalwareADVSTORESHELL

ADVSTORESHELL can perform keylogging.

MalwareAgent Tesla

Agent Tesla can log keystrokes on the victim’s machine.

MalwareAppleSeed

AppleSeed can use GetKeyState and GetKeyboardState to capture keystrokes on the victim’s machine.

MalwareAstaroth

Astaroth logs keystrokes from the victim's machine.

ToolAsyncRAT

AsyncRAT can capture keystrokes on the victim’s machine.

MalwareAttor

One of Attor's plugins can collect user credentials via capturing keystrokes and can capture keystrokes pressed within the window of the injected process.

MalwareBabyShark

BabyShark has a PowerShell-based remote administration ability that can implement a PowerShell or C# based keylogger.

MalwareBADNEWS

When it first starts, BADNEWS spawns a new thread to log keystrokes.

View all 126 software examples

Campaigns3

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team gathered account credentials via a BlackEnergy keylogger plugin.

CampaignCutting Edge

During Cutting Edge, threat actors modified a JavaScript file on the Web SSL VPN component of Ivanti Connect Secure devices to keylog credentials.

CampaignOperation Wocao

During Operation Wocao, threat actors obtained the password for the victim's password manager via a custom keylogger.

References3

  1. Adventures of a Keystroke Open source
    Tinaztepe, E. (n.d.). The Adventures of a Keystroke: An in-depth look into keyloggers on Windows. Retrieved April 27, 2016.
  2. Cisco Blog Legacy Device Attacks Open source
    Omar Santos. (2020, October 19). Attackers Continue to Target Legacy Devices. Retrieved October 20, 2020.
  3. Talos Kimsuky Nov 2021 Open source
    An, J and Malhotra, A. (2021, November 10). North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets. Retrieved December 29, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.