Input Capture

May 1, 2024 ยท View on GitHub

ID E1056
Objective(s) Collection, Credential Access
Related ATT&CK Techniques Input Capture (T1056, T1417)
Version 2.3
Created 1 August 2019
Last Modified 27 April 2024

Input Capture

Malware may record user inputs, typically without the user's knowledge. This is often used to capture sensitive information such as usernames, passwords, credit card numbers, and other personal data. The most common form of input capture is keylogging, where the malware records every keystroke made on a device. However, it can also involve capturing mouse clicks, touch screen interactions, or even voice inputs. The captured data is then usually transmitted to the attacker for use in further malicious activities like identity theft or unauthorized access.

See ATT&CK: Input Capture (T1056, T1417).

Methods

NameIDDescription
Mouse EventsE1056.m01Mouse events are captured.

Use in Malware

NameDateMethodDescription
Rombertik2015--The malware injects itself into a browser and captures user input data. [1]
Ursnif2016--The malware injects HTML into a browser session to collect sensitive online banking information when the victim performs their online banking. [2]
Poison Ivy2005--Poison Ivy can capture audio and video. [4]
Clipminer2011--Clipminer monitors keyboard and mouse activity to determine if the machine is in use. [5]
ElectroRAT2020--ElectroRat monitors keyboard and mouse activity to determine whether the machine is in use. [6]

Detection

Tool: capaMappingAPIs
use .NET library SharpClipboardInput Capture (E1056)--
Tool: CAPEMappingAPIs
antisandbox_mouse_hookInput Capture (E1056)SetWindowsHookExA, SetWindowsHookExW
antisandbox_mouse_hookInput Capture::Mouse Events (E1056.m01)SetWindowsHookExA, SetWindowsHookExW
browser_scanboxInput Capture (E1056)JsEval, COleScript_ParseScriptText, COleScript_Compile

References

[1] https://blogs.cisco.com/security/talos/rombertik

[2] https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/BKDR_URSNIF.SM?_ga=2.129468940.1462021705.1559742358-1202584019.1549394279

[3] https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clipminer-bitcoin-mining-hijacking

[4] https://www.cyber.nj.gov/threat-center/threat-profiles/trojan-variants/poison-ivy

[5] https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf

[6] https://www.intezer.com/blog/research/operation-electrorat-attacker-creates-fake-companies-to-drain-your-crypto-wallets/