T1417.001 Keylogging
Adversaries may log user keystrokes to intercept credentials or other information from the user as the user types them.
Some methods of keylogging include:
- Masquerading as a legitimate third-party keyboard to record user keystrokes.1 On both Android and iOS, users must explicitly authorize the use of third-party keyboard apps. Users should be advised to use extreme caution before granting this authorization when it is requested.
- Abusing accessibility features. On Android, adversaries may abuse accessibility features to record keystrokes by registering an
AccessibilityServiceclass, overriding theonAccessibilityEventmethod, and listening for theAccessibilityEvent.TYPE_VIEW_TEXT_CHANGEDevent type. The event object passed into the function will contain the data that the user typed. *Additional methods of keylogging may be possible if root access is available.
| Item | Value |
|---|---|
| ID | T1417.001 |
| Sub-techniques | T1417.001, T1417.002 |
| Tactics | TA0035, TA0031 |
| Platforms | Android, iOS |
| Version | 1.1 |
| Created | 05 April 2022 |
| Last Modified | 24 October 2025 |
Procedure Examples
| ID | Name | Description |
|---|---|---|
| S0422 | Anubis | Anubis has a keylogger that works in every application installed on the device.18 |
| S1079 | BOULDSPY | BOULDSPY can capture keystrokes.16 |
| S1094 | BRATA | BRATA can log device keystrokes.978 |
| S0655 | BusyGasper | BusyGasper can collect every user screen tap and compare the input to a hardcoded list of coordinates to translate the input to a character.6 |
| S0480 | Cerberus | Cerberus can record keystrokes.21 |
| S1083 | Chameleon | Chameleon has logged keystrokes of an infected device.12 Additionally, Chameleon has stolen PINs, passwords and graphical keys through keylogging functionalities.13 |
| S1054 | Drinik | Drinik can use keylogging to steal user banking credentials.11 |
| S1092 | Escobar | Escobar can collect application keylogs.20 |
| S0478 | EventBot | EventBot can abuse Android’s accessibility service to record the screen PIN.19 |
| S0522 | Exobot | Exobot has used web injects to capture users’ credentials.17 |
| S0408 | FlexiSpy | FlexiSpy can record keystrokes and analyze them for keywords.3 |
| S1231 | GodFather | GodFather has intercepted and recorded sensitive information from the application to include user credentials. GodFather has also leveraged a deceptive overlay that tricks users into submitting their device lock credentials which are captured.15 |
| S0406 | Gustuff | Gustuff abuses accessibility features to intercept all interactions between a user and the device.14 |
| S0407 | Monokle | Monokle can record the user’s keystrokes.5 |
| S1062 | S.O.V.A. | S.O.V.A. can use keylogging to capture user input.10 |
| S1055 | SharkBot | SharkBot can use accessibility event logging to steal data in text fields.4 |
| G0112 | Windshift | Windshift has included keylogging capabilities as part of Operation ROCK.22 |
Mitigations
| ID | Mitigation | Description |
|---|---|---|
| M1012 | Enterprise Policy | When using Samsung Knox, third-party keyboards must be explicitly added to an allow list in order to be available to the end-user.2 |
| M1011 | User Guidance | Users should be wary of granting applications dangerous or privacy-intrusive permissions, such as keyboard registration or accessibility service access. |
References
-
Lenny Zeltser. (2016, July 30). Security of Third-Party Keyboard Apps on Mobile Devices. Retrieved December 21, 2016. ↩
-
Samsung. (2019, August 16). 3rd party keyboards must be whitelisted.. Retrieved November 17, 2024. ↩
-
FlexiSpy. (n.d.). FlexiSpy Monitoring Features. Retrieved September 4, 2019. ↩
-
RIFT: Research and Intelligence Fusion Team. (2022, March 3). SharkBot: a “new” generation Android banking Trojan being distributed on Google Play Store. Retrieved January 18, 2023. ↩
-
Bauer A., Kumar A., Hebeisen C., et al. (2019, July). Monokle: The Mobile Surveillance Tooling of the Special Technology Center. Retrieved September 4, 2019. ↩
-
Alexey Firsh. (2018, August 29). BusyGasper – the unfriendly spy. Retrieved October 1, 2021. ↩
-
Federico Valentini, Francesco Lubatti. (2022, January 24). How BRATA is monitoring your bank account. Retrieved December 18, 2023. ↩
-
Fernando Ruiz. (2021, April 12). BRATA Keeps Sneaking into Google Play, Now Targeting USA and Spain. Retrieved December 18, 2023. ↩
-
Securelist. (2019, August 29). Fully equipped Spying Android RAT from Brazil: BRATA. Retrieved December 18, 2023. ↩
-
ThreatFabric. (2021, September 9). S.O.V.A. - A new Android Banking trojan with fowl intentions. Retrieved February 6, 2023. ↩
-
Cyble. (2022, October 27). Drinik Malware Returns With Advanced Capabilities Targeting Indian Taxpayers. Retrieved November 17, 2024. ↩
-
Cyble Research & Intelligence Labs. (2023, April 13). Banking Trojan targeting mobile users in Australia and Poland. Retrieved August 16, 2023. ↩
-
ThreatFabric. (2023, December 21). Android Banking Trojan Chameleon can now bypass any Biometric Authentication. Retrieved July 7, 2025. ↩
-
Vitor Ventura. (2019, April 9). Gustuff banking botnet targets Australia . Retrieved September 3, 2019. ↩
-
Ortega, F. Pratapagiri, V. (2025, June 18). Your Mobile App, Their Playground: The Dark Side of Virtualization. Retrieved July 16, 2025. ↩
-
Kyle Schmittle, Alemdar Islamoglu, Paul Shunk, Justin Albrecht. (2023, April 27). Lookout Discovers Android Spyware Tied to Iranian Police Targeting Minorities: BouldSpy. Retrieved July 21, 2023. ↩
-
Threat Fabric. (2017, February). Exobot - Android banking Trojan on the rise. Retrieved October 29, 2020. ↩
-
M. Feller. (2020, February 5). Infostealer, Keylogger, and Ransomware in One: Anubis Targets More than 250 Android Applications. Retrieved September 25, 2024. ↩
-
D. Frank, L. Rochberger, Y. Rimmer, A. Dahan. (2020, April 30). EventBot: A New Mobile Banking Trojan is Born. Retrieved June 26, 2020. ↩
-
B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023. ↩
-
Threat Fabric. (2019, August). Cerberus - A new banking Trojan from the underworld. Retrieved June 26, 2020. ↩
-
The BlackBerry Research & Intelligence Team. (2020, October). BAHAMUT: Hack-for-Hire Masters of Phishing, Fake News, and Fake Apps. Retrieved February 8, 2021. ↩