T1056.001 Keylogging in real malware
ATT&CK technique T1056.001 Keylogging appears in 1472 publicly analyzed samples on MalwareAnalyzer by Cyble, 1.3% of the analyzed corpus. Seven-day prevalence is falling (0 recent vs 5 prior). Most associated families: HUILoader, Razy, Mbrlock, Emotet.
Tactics: collection, credential-access
Prevalence in the corpus
- Samples exhibiting T1056.001: 1472
- Share of analyzed corpus: 1.3%
- Last 7 days: 0 · prior 7 days: 5 (falling)
Malware families using T1056.001
Example samples
- Aurora15Connector.exe - malicious
- discord-quest-completer.exe - malicious
- Aurora15Connector.exe - malicious
- Aurora15Connector.exe - malicious
- Aurora15Connector.exe - malicious
- KeePass.exe - malicious
- 75aecef91184b22ef1afe3bdb0ae8c3072dfe1fa08356dd13e2c9899dc7eaf2e - malicious
- c5c7032ed404dec1f9970a019167220ff011b4ce117e7e775262278ba900e195 - malicious
- af569ee985a279ead6234b61ce1957557eb573ae067d06d2c1ab77eda4c4f72d - malicious
- bae6157ecc8725f45770344bd174e6eef095660d3b89e042130bb154909e95ad - malicious
- 8d426aeabdb126c6af992785f00d1dbc176142905c4fa281bb2b6eb6b28b0fe3 - malicious
- 63cd8db640f701949b78fa766ca66aa32e3480b13e4ce1abd85faddb47056e2b - malicious
- 8a5c793dfcdb407b439d00ea9688b620ea6976c4871112293d50a58a3572bf73 - malicious
- 0e5b7823bd4564ef25ad6bf8c9029a3e2eaec88ffe11ec6afe5bdc75c112360d - malicious
- f7c144fef9adbf0b13b0b2e949daad9c650c97db549a8ee984f59232ec80e933 - malicious
- 986ff46ba9d7f1cf9f01ef153b4cee53957c91e47c9a8ed1bcf9c87db4dc0a7e - malicious
- 2512e5fe8931ef5018ed8dcabdbc11409085ec0cb0646ba0dcacccfe7001b1f1 - malicious
- 81183faa59218eab4d03ea4b73c00773d78885075ae12afae7f25f4aeccc7eb8 - malicious
- e5653cfc9bacc7d17e5ce3e3f3387568a4c7337ef66d3b8835a813ff82dc50f9 - malicious
- 8b53307c5bb59263adc68de793c3988d26a134b3e9128c10972364fb44f96995 - malicious
- 4ed8dcd31f3a0c01882abc9aed586af6064dd1048d041491571aee475aa8395d - malicious
- b0f1e23b633f2bdaad255e4cf846a84417ba16b593ad83d5316b5809fdee2cd6 - malicious
- f53693e9871d74c13b61a15b09b430855dde705fa42f4a8b56fbf82bcd151f15 - malicious
- b5cc7050d3e6c41262dd8f1876928b08228c49f53c64ddfeb85f64fcd8085564 - malicious
- 12192ab037706670211011d0a46df32b44909bbdfca3a7285f4b5a74930be3ad - malicious
Canonical technique definition: MITRE ATT&CK T1056.001 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1056.001
- How common is ATT&CK T1056.001 (Keylogging) in real malware?
- ATT&CK technique T1056.001 Keylogging appears in 1472 publicly analyzed samples on MalwareAnalyzer by Cyble, 1.3% of the analyzed corpus. Seven-day prevalence is falling (0 recent vs 5 prior). Most associated families: HUILoader, Razy, Mbrlock, Emotet.
- Is T1056.001 becoming more common?
- Prevalence is falling: 0 samples in the last seven days against 5 in the seven days before. This measures submissions to MalwareAnalyzer by Cyble, so it reflects what is being submitted here rather than global attacker behaviour.
- Which malware families use T1056.001?
- In this corpus T1056.001 is most associated with HUILoader (266), Razy (131), Mbrlock (70), Emotet (59). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1056.001?
- 1.3% of the publicly analyzed corpus (1472 of 114578 samples) exhibits T1056.001. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats