T1056.003: T1056.003
Essential information
- MITRE technique ID
T1056.003- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 27/03/2026 01:10
- Author / Source
- The MITRE Corporation
Aliases
Web Portal Capture
Platforms
windows macos linux
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | collection |
| mitre-attack | credential-access |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (8)
-
The MITRE Corporation Confidence 100
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 08/04/2026 13:02 -
UNC6508 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 16/06/2026 13:48 · Modified 16/06/2026 13:48
-
The MITRE Corporation Confidence 100
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
BlueDelta usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:08 · Modified 21/12/2025 05:08
-
The MITRE Corporation Confidence 100
[Kimsuky](https://attack.mitre.org/groups/G0094) is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
The MITRE Corporation Confidence 100
[Fox Kitten](https://attack.mitre.org/groups/G0117) is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[FIN7](https://attack.mitre.org/groups/G0046) is a financially-motivated threat group that has been active since 2013. [FIN7](https://attack.mitre.org/groups/G0046) has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
Telekopye usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:12 · Modified 21/12/2025 08:12
Malware (17)
- IceApple
-
HealthKick usesFamilyPublished 28/04/2026 07:09 · Modified 28/04/2026 07:09
-
INFINITERED usesFamilyPublished 15/06/2026 19:33 · Modified 15/06/2026 19:33
-
XWorm usesFamilyPublished 27/03/2026 08:45 · Modified 27/03/2026 08:45
-
HeadLace usesFamilyPublished 05/08/2024 08:30 · Modified 05/08/2024 08:30
-
Telekopye usesFamilyPublished 17/11/2024 00:25 · Modified 17/11/2024 00:25
-
MageCart usesFamilyPublished 13/02/2025 01:13 · Modified 13/02/2025 01:13
-
httd usesFamilyPublished 18/03/2026 10:51 · Modified 18/03/2026 10:51
-
Carbanak - S0030 usesFamilyPublished 11/07/2024 11:51 · Modified 11/07/2024 11:51
-
Rhadamanthys usesFamilyPublished 29/04/2026 02:24 · Modified 29/04/2026 02:24
- WARPWIRE
-
Gracewire usesFamilyPublished 11/07/2024 11:51 · Modified 11/07/2024 11:51
- Carbanak
-
GOVERSHELL usesFamilyPublished 28/04/2026 07:09 · Modified 28/04/2026 07:09
-
EugenLoader usesFamilyPublished 11/07/2024 11:51 · Modified 11/07/2024 11:51
-
Gremlin stealer usesFamilyPublished 15/05/2026 15:23 · Modified 15/05/2026 15:23
-
SpyPress.Roundish usesFamilyPublished 18/03/2026 10:51 · Modified 18/03/2026 10:51
Reports (15)
-
12 MITREs 1 Malware 8 Observables 1 APTPublished 15/06/2026 19:33 · Modified 16/06/2026 11:48
-
16 MITREsPublished 15/06/2026 14:53 · Modified 15/06/2026 17:15
-
AlienVault Confidence 100 28 MITREs 5 IOCs 5 ObservablesPublished 11/06/2026 23:09 · Modified 15/06/2026 19:16 · threat-report
-
20 MITREs 19 ObservablesPublished 10/06/2026 10:57 · Modified 10/06/2026 11:00
-
AlienVault Confidence 100 21 MITREs 2 Malwares 132 IOCs 132 ObservablesPublished 28/04/2026 09:09 · Modified 28/04/2026 14:36 · threat-report
-
The AI Frame Campaign Continues related20 MITREs 1 ObservablePublished 24/04/2026 05:05 · Modified 27/04/2026 14:38
-
4 MITREsPublished 20/04/2026 13:20 · Modified 20/04/2026 13:53
-
20 MITREs 2 Malwares 5 Observables 1 APTPublished 18/03/2026 10:51 · Modified 18/03/2026 11:20
-
8 MITREs 23 Observables 1 APTPublished 17/12/2025 20:07 · Modified 21/12/2025 19:35
-
10 MITREs 1 MalwarePublished 13/02/2025 01:13 · Modified 13/02/2025 10:12
-
9 MITREsPublished 10/01/2025 01:21 · Modified 10/01/2025 08:41
-
6 MITREsPublished 22/11/2024 04:49 · Modified 22/11/2024 09:24
-
9 MITREs 1 Malware 1 APTPublished 17/11/2024 00:25 · Modified 18/11/2024 17:03
-
6 MITREs 4 Malwares 94 Observables 1 APTPublished 11/07/2024 11:51 · Modified 11/07/2024 12:06
-
18 MITREs 1 Malware 30 Observables 1 APTPublished 31/05/2024 14:17 · Modified 31/05/2024 14:34
Attack patterns (MITRE) (1)
-
T1056 subtechnique-ofInput Capture
Campaign (2)
- Triton Safety Instrumented System Attack uses
- Cutting Edge uses
Course Of Action (1)
- Privileged Account Management mitigates