T1056.002: T1056.002
Essential information
- MITRE technique ID
T1056.002- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 27/03/2026 01:11
- Author / Source
- The MITRE Corporation
Aliases
GUI Input Capture
Platforms
windows macos linux
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | collection |
| mitre-attack | credential-access |
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (15)
-
The MITRE Corporation Confidence 100
[APT37](https://attack.mitre.org/groups/G0067) is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
TA2723 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 20:39 · Modified 21/12/2025 20:39
-
MioLab usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 04/05/2026 13:29 · Modified 04/05/2026 13:29
-
Grandoreiro usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:03 · Modified 21/12/2025 03:03
-
FIN4 usesThe MITRE Corporation Confidence 100
[FIN4](https://attack.mitre.org/groups/G0085) is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly regarding healthcare and pharmaceutical companies, since at least 2013.(Citation: FireEye …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
RedCurl usesThe MITRE Corporation Confidence 100
[RedCurl](https://attack.mitre.org/groups/G1039) is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
TA2726, TA2727 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 10:04 · Modified 21/12/2025 10:04
-
ShadyPanda usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 19:23 · Modified 21/12/2025 19:23
-
ERMAC usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 16:06 · Modified 21/12/2025 16:06
-
BlindEagle usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:53 · Modified 27/05/2026 15:52
-
BlueDelta usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:08 · Modified 21/12/2025 05:08
-
GhostClaw usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 27/03/2026 01:01 · Modified 27/03/2026 01:01
-
Hydra Saiga usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 17/03/2026 12:16 · Modified 17/03/2026 12:16
-
Gamaredon usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 20:11 · Modified 20/12/2025 20:11
-
UNK_DeadDrop usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 09/06/2026 10:58 · Modified 09/06/2026 10:58
Malware (25 / 73)
-
AsyncRAT usesFamilyPublished 11/06/2026 16:31 · Modified 11/06/2026 16:31
-
SUPERNOVA - S0578 usesFamilyPublished 30/04/2026 14:20 · Modified 30/04/2026 14:20
-
GammaLoad usesFamilyPublished 04/06/2026 13:57 · Modified 04/06/2026 13:57
-
GammaWipe usesFamilyPublished 04/06/2026 13:57 · Modified 04/06/2026 13:57
-
Overlord usesFamilyPublished 08/06/2026 10:05 · Modified 08/06/2026 10:05
-
Gholoader usesFamilyPublished 18/02/2025 15:38 · Modified 18/02/2025 15:38
- Proton
- Calisto
- Bundlore
-
Mekotio usesFamilyPublished 19/05/2026 22:26 · Modified 19/05/2026 22:26
-
Cuckoo Stealer usesFamilyPublished 19/02/2026 15:26 · Modified 19/02/2026 15:26
-
Marcher usesFamilyPublished 18/02/2025 15:38 · Modified 18/02/2025 15:38
-
Ermac usesFamilyPublished 19/03/2026 11:00 · Modified 19/03/2026 11:00
-
QuasarRAT usesFamilyPublished 25/02/2026 11:35 · Modified 25/02/2026 11:35
-
GhostLoader usesFamilyPublished 17/06/2026 18:20 · Modified 17/06/2026 18:20
-
EtherRAT usesFamilyPublished 16/06/2026 14:27 · Modified 16/06/2026 14:27
-
ThreatNeedle - S0665 usesFamilyPublished 11/05/2026 08:50 · Modified 11/05/2026 08:50
-
Mispadu usesFamilyPublished 18/12/2024 19:17 · Modified 18/12/2024 19:17
-
MuddyViper usesFamilyPublished 03/01/2026 11:05 · Modified 03/01/2026 11:05
-
OtterCookie usesFamilyPublished 08/06/2026 10:05 · Modified 08/06/2026 10:05
-
AMOS Stealer usesFamilyPublished 11/05/2026 11:49 · Modified 11/05/2026 11:49
-
Chisel usesFamilyPublished 16/06/2026 14:27 · Modified 16/06/2026 14:27
-
ClickFix usesFamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
-
Remcos usesFamilyPublished 05/05/2026 18:45 · Modified 05/05/2026 18:45
-
SocGholish usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
Reports (25 / 26)
-
AlienVault Confidence 100 19 MITREs 4 Malwares 22 IOCs 22 ObservablesPublished 16/06/2026 16:27 · Modified 16/06/2026 17:19 · threat-report
-
20 MITREs 4 Malwares 18 Observables 1 APTPublished 08/06/2026 10:05 · Modified 09/06/2026 09:00
-
18 MITREs 5 Malwares 2 Observables 1 APTPublished 04/06/2026 13:57 · Modified 05/06/2026 09:12
-
30 MITREs 1 Malware 3 ObservablesPublished 30/05/2026 11:25 · Modified 02/06/2026 10:00
-
19 MITREs 2 Malwares 1 ObservablePublished 11/05/2026 08:50 · Modified 11/05/2026 09:56
-
AlienVault Confidence 100 16 MITREs 2 Malwares 7 IOCs 7 ObservablesPublished 05/05/2026 20:45 · Modified 06/05/2026 10:10 · threat-report
-
20 MITREs 2 Malwares 10 Observables 1 APTPublished 30/04/2026 14:20 · Modified 04/05/2026 11:29
-
AlienVault Confidence 100 20 MITREs 1 Malware 13 IOCs 13 ObservablesPublished 25/04/2026 06:37 · Modified 27/04/2026 14:58 · threat-report
-
AlienVault Confidence 100 23 MITREs 2 Malwares 53 IOCs 53 ObservablesPublished 20/04/2026 12:25 · Modified 20/04/2026 16:54 · threat-report
-
10 MITREs 2 Malwares 16 Observables 1 APTPublished 23/03/2026 09:27 · Modified 27/03/2026 00:02
-
16 MITREs 6 ObservablesPublished 21/01/2026 18:46 · Modified 22/01/2026 14:49
-
11 MITREs 8 Observables 1 APTPublished 18/12/2025 13:28 · Modified 21/12/2025 19:39
-
8 MITREs 23 Observables 1 APTPublished 17/12/2025 20:07 · Modified 21/12/2025 19:35
-
12 MITREs 1 ObservablePublished 10/12/2025 18:35 · Modified 21/12/2025 18:57
-
20 MITREs 3 Malwares 1 APTPublished 03/12/2025 20:19 · Modified 21/12/2025 18:23
-
25 MITREs 2 ObservablesPublished 01/12/2025 19:55 · Modified 21/12/2025 18:18
-
10 MITREs 3 Malwares 1 APTPublished 15/08/2025 05:29 · Modified 15/08/2025 13:07
-
13 MITREsPublished 15/03/2025 07:22 · Modified 17/03/2025 10:08
-
14 MITREs 7 Malwares 10 Observables 1 APTPublished 18/02/2025 15:38 · Modified 18/02/2025 17:55
-
18 MITREs 3 Malwares 26 ObservablesPublished 04/02/2025 18:19 · Modified 04/02/2025 18:46
-
8 MITREs 5 ObservablesPublished 02/01/2025 15:28 · Modified 02/01/2025 15:31
-
16 MITREs 17 MalwaresPublished 21/10/2024 15:16 · Modified 21/10/2024 16:54
-
9 MITREs 13 ObservablesPublished 14/10/2024 10:54 · Modified 14/10/2024 11:14
-
10 MITREs 1 Malware 8 ObservablesPublished 27/09/2024 09:17 · Modified 27/09/2024 09:40
-
19 MITREs 4 Malwares 16 Observables 1 APTPublished 05/09/2024 16:47 · Modified 05/09/2024 17:17
Vulnerabilities (CVE) (1)
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for …
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 12/04/2017
- Modified
- 22/04/2026
Attack patterns (MITRE) (1)
-
T1056 subtechnique-ofInput Capture
Course Of Action (1)
- User Training mitigates
Tool (1)
-
SILENTTRINITY usesThe MITRE Corporation Confidence 100
[SILENTTRINITY](https://attack.mitre.org/software/S0692) is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers written in Powershell, C, and Boo. [SILENTTRINITY](https://attack.mitre.org/software/S0692) was used in a …
Published 23/03/2022 20:34 · Modified 27/03/2026 01:07