# T1056.001 Keylogging

> As of 2026-10-05, T1056.001 (Keylogging) appears in 134 tracked threats, first reported 2026-01-14 and most recently 2026-10-04, with linked actors including APT38, APT43, Kimsuky; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 134 (11 critical, 113 high, 10 medium)
- **First seen:** 2026-01-14
- **Last seen:** 2026-10-04
- **Threat actors:** 50
- **Detection rules:** 164 (counts only; Blue tier and above)

## Key facts

- **ID:** T1056.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access, Collection
- **Matrix:** Enterprise
- **Parent:** T1056
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1056/001/

## Activity timeline

T1056.001 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 47 reports, and 134 of the 134 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1056.001 Keylogging is catalogued by MITRE ATT&CK under the Credential Access and Collection tactics in the Enterprise matrix, as a sub-technique of [T1056 Input Capture](https://intel.threadlinqs.com/technique/T1056). Threadlinqs maps 134 of 2623 tracked threats (5.1%) to it; by severity that is 11 critical, 113 high, 10 medium.

Threats that use T1056.001 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (106 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (93 threats), [T1113 Screen Capture](https://intel.threadlinqs.com/technique/T1113) (88 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (87 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (84 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

50 tracked threat actors appear in the threats that use T1056.001; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (7), [APT43](https://intel.threadlinqs.com/actor/APT43) (6), [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) (6), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (5), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (5).

## Data sources

Telemetry that can reveal T1056.001, per MITRE ATT&CK.

- Driver — Driver Load
- Process — OS API Execution
- Windows Registry — Windows Registry Key Modification

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 7
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 6
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 6
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 5
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 5
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 4
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 4
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 4
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 3
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 3
- [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) — 3
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 3

## Tracked threats

The 30 most recent of 134 tracked threats that use T1056.001.

- [Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…](https://intel.threadlinqs.com/threat/TL-2026-2919) — high — 2026-10-04
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…](https://intel.threadlinqs.com/threat/TL-2026-2901) — high — 2026-10-04
- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFA](https://intel.threadlinqs.com/threat/TL-2026-2834) — high — 2026-10-01
- [AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…](https://intel.threadlinqs.com/threat/TL-2026-2800) — high — 2026-09-30
- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — high — 2026-09-29
- [Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…](https://intel.threadlinqs.com/threat/TL-2026-2764) — high — 2026-09-28
- [Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…](https://intel.threadlinqs.com/threat/TL-2026-2654) — high — 2026-09-25
- [North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via…](https://intel.threadlinqs.com/threat/TL-2026-2581) — high — 2026-09-19
- [SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2554) — high — 2026-09-17
- [KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious…](https://intel.threadlinqs.com/threat/TL-2026-2544) — high — 2026-09-16
- [BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL…](https://intel.threadlinqs.com/threat/TL-2026-2519) — high — 2026-09-15
- [The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2402) — high — 2026-09-08
- [DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patients](https://intel.threadlinqs.com/threat/TL-2026-2328) — high — 2026-09-04
- [Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chain](https://intel.threadlinqs.com/threat/TL-2026-2305) — high — 2026-09-03
- [REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…](https://intel.threadlinqs.com/threat/TL-2026-2353) — high — 2026-09-02
- [Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International…](https://intel.threadlinqs.com/threat/TL-2026-2303) — medium — 2026-09-02
- [Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts](https://intel.threadlinqs.com/threat/TL-2026-2296) — high — 2026-09-02
- [Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholing](https://intel.threadlinqs.com/threat/TL-2026-2284) — high — 2026-09-01
- [JSCeal Cryptocurrency Stealer: Check Point Details Static Deobfuscation of Compiled V8 Bytecode Payloads](https://intel.threadlinqs.com/threat/TL-2026-2259) — high — 2026-08-31
- [Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breach](https://intel.threadlinqs.com/threat/TL-2026-2219) — high — 2026-08-29
- [Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Theft](https://intel.threadlinqs.com/threat/TL-2026-2229) — high — 2026-08-28
- [July 2026 Domestic APT Attack Trends (South Korea): LNK-Based Spear Phishing Delivering XenoRAT and…](https://intel.threadlinqs.com/threat/TL-2026-2180) — high — 2026-08-28
- [Void Dokkaebi Ships Cython-Compiled InvisibleFerret Malware as .pyd/.so Files to Evade Script Detection](https://intel.threadlinqs.com/threat/TL-2026-2145) — high — 2026-08-25
- [Agent Tesla v4 Hidden Behind Unicode-Emoji-Obfuscated JScript Evades Detection in BEC Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2108) — high — 2026-08-22
- [Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…](https://intel.threadlinqs.com/threat/TL-2026-2091) — high — 2026-08-21
- [SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2200) — high — 2026-08-19
- [StopAndProtect: Compromised WordPress Sites Used as Malware Distribution Infrastructure for Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-2057) — high — 2026-08-18
- [PhantomStealer Infostealer Distributed via Phishing Campaign with BYOVD Security Software Killer](https://intel.threadlinqs.com/threat/TL-2026-2055) — high — 2026-08-18
- [DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling](https://intel.threadlinqs.com/threat/TL-2026-2015) — high — 2026-08-14
- [Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT](https://intel.threadlinqs.com/threat/TL-2026-1996) — high — 2026-08-12

## Related CVEs

CVEs referenced by the tracked threats that use T1056.001, most frequent first.

- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2017-8291](https://intel.threadlinqs.com/cve/CVE-2017-8291)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)

## Detection coverage

Threadlinqs maintains 164 detection rules mapped to T1056.001 (SPL 36, KQL 67, Sigma 61). Rule content is available to Blue tier accounts and above; this page shows counts only.

164 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1056 Input Capture](https://intel.threadlinqs.com/technique/T1056) — 285 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1056.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
