T1056.001 - Keylogging - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
59
occurrences
First Seen
November 21, 2025
Last Seen
August 26, 2026

T1056.001 Keylogging is a MITRE ATT&CK technique where attackers capture user keystrokes to harvest credentials and other sensitive data.

Overview

T1056.001 Keylogging is a MITRE ATT&CK technique where attackers capture user keystrokes to harvest credentials and other sensitive data. It can be implemented via OS-level keyloggers, browser-based scripts, or malware components, enabling credential theft and data exfiltration across platforms. This technique remains a foundational risk in cybersecurity due to its direct access to user inputs and login information.

Related Threat Clusters

Recent Intelligence Reports

  • Dark Caracal Adds New Malware to Cyber Espionage Arsenal — Darkreading · August 26, 2026
  • Hanoi police warn of several particularly dangerous malware strains. — Vietnam.Vn · August 26, 2026
  • Russian snoops add OAuth abuse to targeted phishing campaigns — Theregister · August 21, 2026
  • Inside the Phishing Scam That Could Drain Your Retirement Savings — Streamlinefeed.Co.Ke · August 19, 2026
  • [SecurityIntel] 02 Aug | Coldcard Wallet Flaw Leads to $70M Theft — Buttondown · August 2, 2026
  • Analyzing Flying Eagle Android RAT: APK Builder, C2 Panel, Banking Overlays, and a Successor Called Night Dragon — Reddit · July 28, 2026
  • The British Supreme Court has rejected Bahrain's request for immunity in the spyware case — Ua.News · July 27, 2026
  • Golden Chickens malware-as-a — Feeds.Feedburner · July 24, 2026

CVSS v3.1 Breakdown