FORENSIA

ATT&CK · T1056.002 · sub-technique

GUI Input Capture

Tactics: collection, credential-access

About

Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt. When programs are executed that need additional privileges than are present in the current user context, it is common for the operating system to prompt the user for proper credentials to authorize the elevated privileges for the task (ex: Bypass User Account Control). Adversaries may mimic this functionality to prompt users for credentials with a seemingly legitimate prompt for a number of reasons that mimic normal usage, such as a fake installer requiring additional access or a fake malware removal suite. This type of prompt can be used to collect credentials via various languages such as AppleScript and PowerShell. On Linux systems adversaries may launch dialog boxes prompting users for credentials from malicious shell scripts or the command line (i.e. Unix Shell). Adversaries may also mimic common software authentication requests, such as those from browsers or email clients. This may also be paired with user activity monitoring (i.e., Browser Information Discovery and/or Application Window Discovery) to spoof prompts when users are naturally accessing sensitive sites/data.

Platforms: Linux, macOS, WindowsParent: T1056 Input CaptureMITRE ATT&CK ↗

Used by actors

2 known groups

Software

13 malware/tools implement this

CalistoKeydnapiKittenProtonDokMetamorfoBundloreXCSSETSILENTTRINITYMispaduCuckoo StealerMuddyViperLP-Notes

Corpus indicators tagged with this technique

157 indicators in the corpus carry T1056.002.

IndicatorTypeFamilySevSrc
5e06af187b45476ade0d953e834fced6197d0a33ac60c2575877660e26ab15e8sha256phishing801
4ca2c863d740bb7022776dccabd8ae34bb9998768928042d76ebcf08984eefcbsha256phishing801
540ee1936e61d2344b5ebc93485589a351ec2f113a9b4940ae16f3baa4807392sha256phishing801
5a2ed557c357ba8f96f2d55a8a00695987806b5df766cd1dfdab0cbed111774asha256phishing801
4c9fdc2823da505ef339d43c6ad38499b7e3447736733e42b5ab6b1afcfd42aasha256phishing801
d4eb4ff02df659fdeec17d36b77084627469623bb3c7d16383d257404b52d1c3sha256phishing801
21b24f7ee1f6bdbbb670f0394d66009ee0daa8ced57048298da715e88f7a7cddsha256phishing801
48723a33bab89f174750576f9a62da35b3b9e5ac31a5a8f1ce9859a1b35bf8b8sha256phishing801
62761f38ed194c59abe15c49f09f0ebc431ac852c965180c9327ed84d3a454fbhashphishing802
5837e47198a20877e1b04b270c36d9194206ee38d4f32fe3151b3c3b396c4f0dsha256phishing801
0d681bd160db1b1df5db321a6d2dd9ae81b2609bhash801
1e77992666acbbfa0d01fcefa9cc8fbdac291e0681b35745be27c6dfb159a375sha256phishing801
fadbb8061715128bebecf7bc59132b6bb04fe8cc39b965aa5b8722dffe28d7e7sha256phishing801
e6e78eb2e9bd41a4bc62f7ad54d095ea9813864bebe37172ae30a1afa631fe14sha256phishing801
d5e9288693aa745dc89368deac677e7ea1ec81e663283af30838cdae189b7a7ehashphishing802
44f6101dd8171133f53317bfd752300ehash802
4537b37b65e9dc35640d750f3fa7f4944534f6b1hash803
18fd38988d58dd930f5992d448cc09a9400c1eafba76b820b9a83239ac48cf4esha256phishing801
fab69acd743f4111b749e3268690825c38822e62hash802
52886aab179f26421678ff23af1b0fabf0a17ffbb534369cdbbac8008cbed8e7hashphishing802
9e5b1e10ad6904d3f5b48d38470cd57263974640a27d13cf793ef026d3d6b886hash802
91b9381d19b2e6a2db5cc0307167979b502731cb3fb50da684479e9ed35261aahashphishing802
4c0d9b802c075be79e9edb52d88f8dd72e6904f5c58267213745818470945c78hashphishing802
91e523a46f3bb860ac2e5800b7e1ec89d75a2408410b9cd25eebc17c8d7a92bchash802
808e7154b7af2bc7a4b28d577297c55f77221c355191cbe00f9f1810b6d4a619hashphishing802
19ac18a50abb48dc0ea9524850acfaec49359e6b3bcc67c6193c2d56da812c71sha256phishing801
bb10adac5b0124efedfe71102c1d5638135ec9e1cde8c8cb3353c5ed91bb9f81hashphishing802
99813f3d0625e880158c68039c0e2fbf488db0be3db77cd1ce6d382644193f0ehash802
d3ebce2f05fe91a8260e87fd11a6ea17c156703d081b3f91d9bbe5fd6aeedc10hashphishing802
65c1a998bac48e02b52b1c850cd500e9fb87521e21755c3a4a491243f5f9a700sha256phishing801

Showing the top 30 by severity of 157.