T1056 - Input Capture - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
197
occurrences
First Seen
November 12, 2025
Last Seen
August 31, 2026

T1056 - Input Capture covers techniques that capture user input, including keystrokes and clipboard data, to steal credentials or sensitive information.

Overview

T1056 - Input Capture covers techniques that capture user input, including keystrokes and clipboard data, to steal credentials or sensitive information. Recent reports show Android-based FvncBot capturing keystrokes and dropping payloads, and the Ferocious Kitten APT deploying MarkiRAT to perform keystroke and clipboard logging, underscoring the technique's cross-platform relevance. This remains a significant attack vector for credential theft and data exfiltration across actors and environments.

Related Threat Clusters

Recent Intelligence Reports

  • New Ploutus Variant — cloud.google.com · August 31, 2026
  • ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool — Securityaffairs.Co · August 31, 2026
  • ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions — Thehackernews · August 31, 2026
  • ValleyRAT masquerading as adware — Securelist · August 31, 2026
  • Chrome Extension Malware Campaign Hits 19 Browser Add Ons — Coingabbar · August 29, 2026
  • Cj6dx4886rpo — www.bbc.com · August 27, 2026
  • Warning: Two particularly dangerous malware strains. — Vietnam.Vn · August 27, 2026
  • Warning: Some malware strains are particularly dangerous. — Vietnam.Vn · August 27, 2026

CVSS v3.1 Breakdown