TACTIC: CREDENTIAL ACCESS
Keylogging (T1056.001): real cases
MITRE Definition ↗ Adversaries record keystrokes to harvest passwords and confidential communications.
Key Facts
Technique ID
T1056.001
Credential Access
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
- ATT&CK Technique Identifier: T1056.001.
- Tactical Phase: Credential Access.
- Substantiated in 1 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)
sentenced 2018-03-27
Primary Source Evidence Excerpt: Indictment ¶ 22, Page 12
"Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions."
U.S. District Court for the Western District of Washington
View full case dossier →