Activity timeline
T1056 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 81 reports, and 284 of the 285 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1056 Input Capture is catalogued by MITRE ATT&CK under the Credential Access and Collection tactics in the Enterprise matrix. Threadlinqs maps 285 of 2623 tracked threats (10.9%) to it; by severity that is 51 critical, 202 high, 31 medium.
Threats that use T1056 most often also use T1027 Obfuscated Files or Information (217 threats), T1071 Application Layer Protocol (207 threats), T1036 Masquerading (198 threats), T1566 Phishing (195 threats), T1204 User Execution (194 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
99 tracked threat actors appear in the threats that use T1056; the most frequent are APT38 (8), Sapphire Sleet (7), Andariel (6), Lazarus Group (6), Stardust Chollima (6).
Data sources
Telemetry that can reveal T1056, per MITRE ATT&CK.
- Command — Command Execution
- Driver — Driver Load
- File — File Creation, File Modification
- Module — Module Load
- Process — OS API Execution, Process Creation, Process Metadata
- Windows Registry — Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 285 tracked threats that use T1056.
- TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplacemedium
- North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…high
- KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…high
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvestershigh
- Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teamsmedium
- QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Servicehigh
- PEEP: Chromium Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Executionhigh
- REVSTEALER (REF2859): Emerging Windows infostealer with App-Bound encryption bypass, Polygon blockchain C2…high
- ASCII Smuggling Phishing Campaign Uses Invisible Unicode Tags-Block Characters to Evade Filters, Targeting…high
- BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target…high
- Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…high
- ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloadinghigh
- Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal…high
- TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and Indiahigh
- Dark Caracal Expands Espionage Arsenal with GoCaracal Framework and AsioGate Backdoorhigh
- AnonyMousKIT: AI-Powered Phishing-as-a-Service Platform Stealing Apple IDs from Stolen iPhoneshigh
- SynkLoader: New Multi-Module Malware Family Distributed via Microsoft Teams Phishing Campaign Targeting…high
- iAuthFlow V2 Phishing Toolkit Enrolls Attacker-Controlled Passkeys That Survive Password Resetshigh
- SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governmentscritical
- SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asiahigh
- Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targetshigh
- Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRighigh
- Origin-Validation Bypass in Connective (Nitro Software Belgium) eID Browser Extension Enables PIN Theft…critical
- CSS Bomb: JavaScript-Free CSS Keylogging and Token-Theft Attacks Against Gmail, Outlook, Yahoo Mail, AOL…high
- Critical Cisco IMC Argument Injection (CVE-2026-20200) Enables Root RCE on UCS C-Series M7/M8 Standalone…critical
- Greatness PhaaS — AiTM phishing platform targeting Microsoft 365 and multi-platform credentials via spoofed…high
- Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials…high
- AI-Enhanced Phishing and Adversary-in-the-Middle (AiTM) Phishing-as-a-Service Ecosystem — 2025-2026 Threat…high
- XCSSET v40 macOS Malware Targeting Developers via Compromised Xcode Projectshigh
- Apple challenges UK Home Office Technical Capability Notice over encrypted iCloud access (Advanced Data…high
Detection coverage
Threadlinqs maintains 55 detection rules mapped to T1056 (SPL 16, KQL 23, Sigma 16). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1056.001 Keylogging — 134 tracked threats
- T1056.002 GUI Input Capture — 36 tracked threats
- T1056.003 Web Portal Capture — 58 tracked threats
- T1056.004 Credential API Hooking — 14 tracked threats