26
Groups Using This
2
Tactics
4
Platforms
50
Prevalence Rank
Description

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems. Keylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes. Some methods include: * Hooking API callbacks used for processing keystrokes. Unlike Credential API Hooking, this focuses solely on API functions intended for processing keystroke data. * Reading raw keystroke data from the hardware buffer. * Windows Registry modifications. * Custom drivers. * Modify System Image may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.

View MITRE record โ†—

Platforms
LinuxmacOSNetwork DevicesWindows
Groups Using T1056.001 (26)
G0094
Kimsuky
๐Ÿ‡ท๐Ÿ‡บ Russia130 techniques19 software
G0032
Lazarus Group
๐Ÿ‡ฐ๐Ÿ‡ต North Korea93 techniques26 software
G0007
APT28
๐Ÿ‡ท๐Ÿ‡บ Russia93 techniques29 software
G0096
APT41
๐Ÿ‡จ๐Ÿ‡ณ China82 techniques32 software
G1017
Volt Typhoon
๐Ÿ‡จ๐Ÿ‡ณ China81 techniques17 software
G0034
Sandworm Team
๐Ÿ‡ท๐Ÿ‡บ Russia79 techniques27 software
G0050
APT32
๐Ÿ‡ป๐Ÿ‡ณ Vietnam78 techniques15 software
G0059
Magic Hound
๐Ÿ‡ฎ๐Ÿ‡ท Iran78 techniques13 software
G0049
OilRig
๐Ÿ‡ฎ๐Ÿ‡ท Iran76 techniques30 software
G0027
Threat Group-3390
๐Ÿ‡จ๐Ÿ‡ณ China57 techniques24 software
G0082
APT38
๐Ÿ‡ฐ๐Ÿ‡ต North Korea56 techniques6 software
G0087
APT39
๐Ÿ‡ฎ๐Ÿ‡ท Iran53 techniques11 software
G1016
FIN13
53 techniques4 software
G0045
menuPass
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques25 software
G0004
Ke3chang
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques11 software
G0022
APT3
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G1001
HEXANE
36 techniques12 software
G1044
APT42
๐Ÿ‡ฎ๐Ÿ‡ท Iran32 techniques2 software
G1023
APT5
๐Ÿ‡จ๐Ÿ‡ณ China29 techniques13 software
G0012
Darkhotel
๐Ÿ‡ฐ๐Ÿ‡ท South Korea24 techniques0 software
G0131
Tonto Team
๐Ÿ‡จ๐Ÿ‡ณ China15 techniques6 software
G0085
FIN4
12 techniques0 software
G0068
PLATINUM
11 techniques3 software
G0054
Sowbug
9 techniques2 software
G0130
Ajax Security Team
๐Ÿ‡ฎ๐Ÿ‡ท Iran6 techniques2 software
G0043
Group5
๐Ÿ‡ฎ๐Ÿ‡ท Iran4 techniques2 software
โ†‘