TACTIC: CREDENTIAL ACCESS

Keylogging (T1056.001): real cases

MITRE Definition ↗
Adversaries record keystrokes to harvest passwords and confidential communications.

Key Facts

Technique ID
T1056.001
Credential Access
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1056.001.
  • Tactical Phase: Credential Access.
  • Substantiated in 1 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Indictment ¶ 22, Page 12
"Carbanak malware contained keystroke logging modules to capture administrative credentials entered in terminal sessions."
U.S. District Court for the Western District of Washington View full case dossier →