T1056.001 Keylogging is a MITRE ATT&CK technique where attackers capture user keystrokes to harvest credentials and other sensitive data.
Overview
T1056.001 Keylogging is a MITRE ATT&CK technique where attackers capture user keystrokes to harvest credentials and other sensitive data. It can be implemented via OS-level keyloggers, browser-based scripts, or malware components, enabling credential theft and data exfiltration across platforms. This technique remains a foundational risk in cybersecurity due to its direct access to user inputs and login information.
Related Threat Clusters
-
Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks
A China-linked threat actor known as Red Menshen has been conducting a long-term espionage campaign targeting global telecommunications networks using a stealthy Linux kernel backdoor called BPFdoor. This malware…
16 articles · Updated March 26, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
Russia's Bauman University: Training Ground for GRU Hackers and Spies
Bauman Moscow State Technical University is revealed to host a secret department training students for the GRU, Russia's military intelligence. Leaked documents show that over 2,000 students have been trained in…
15 articles · Updated May 7, 2026 -
Russian Cyber Espionage Clusters Exploit OAuth and Phishing Techniques
Google's Threat Intelligence Group (GTIG) is tracking three Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—targeting individuals in academia, defense, and government across Europe and the U.S. These…
14 articles · Updated August 21, 2026 -
Dark Caracal Unveils GoCaracal Malware for Cyber Espionage
The Lebanon-linked Dark Caracal threat group has introduced a new malware framework named GoCaracal, enhancing its cyberespionage capabilities. Discovered by Arctic Wolf during an intrusion investigation in Venezuela,…
13 articles · Updated August 26, 2026 -
New NarwhalRAT Malware Targets Korean Users via Phishing Emails
A new malware named NarwhalRAT has been discovered targeting Korean users through phishing emails impersonating the Microsoft security team. The malware, linked to the North Korean hacking group APT37, can perform over…
9 articles · Updated June 15, 2026 -
Russian UAT-11795 Targets Users with Trojans in Legitimate Software
A Russian threat actor known as UAT-11795 has been deploying the Starland RAT and WLDR agent since June 2025, primarily targeting users in the U.S., Germany, Romania, and Venezuela. The group uses trojanized installers…
6 articles · Updated July 17, 2026 -
Oblivion RAT: New Android Malware as a Service Threatens Users and Enterprises
Oblivion RAT is a sophisticated Android remote access trojan (RAT) sold as a Malware-as-a-Service (MaaS) platform. It operates on a subscription model, providing threat actors with tools like a web-based APK builder and…
4 articles · Updated March 21, 2026 -
Critical Vulnerabilities in IP KVM Devices Expose Network Risks
Cybersecurity researchers have identified nine critical vulnerabilities in low-cost IP KVM devices, including Sipeed NanoKVM, which could allow unauthenticated attackers to gain extensive control over compromised hosts.…
4 articles · Updated March 19, 2026
Recent Intelligence Reports
- Dark Caracal Adds New Malware to Cyber Espionage Arsenal — Darkreading · August 26, 2026
- Hanoi police warn of several particularly dangerous malware strains. — Vietnam.Vn · August 26, 2026
- Russian snoops add OAuth abuse to targeted phishing campaigns — Theregister · August 21, 2026
- Inside the Phishing Scam That Could Drain Your Retirement Savings — Streamlinefeed.Co.Ke · August 19, 2026
- [SecurityIntel] 02 Aug | Coldcard Wallet Flaw Leads to $70M Theft — Buttondown · August 2, 2026
- Analyzing Flying Eagle Android RAT: APK Builder, C2 Panel, Banking Overlays, and a Successor Called Night Dragon — Reddit · July 28, 2026
- The British Supreme Court has rejected Bahrain's request for immunity in the spyware case — Ua.News · July 27, 2026
- Golden Chickens malware-as-a — Feeds.Feedburner · July 24, 2026