Description
[KeyBoy](https://attack.mitre.org/software/S0387) is malware that has been used in targeted campaigns against members of the Tibetan Parliament in 2016.(Citation: CitizenLab KeyBoy Nov 2016)(Citation: PWC KeyBoys Feb 2017)
External References
Techniques Used by This Malware
- T1001.003 — Protocol or Service Impersonation
- T1016 — System Network Configuration Discovery
- T1027.013 — Encrypted/Encoded File
- T1056.001 — Keylogging
- T1059.001 — PowerShell
- T1059.003 — Windows Command Shell
- T1059.005 — Visual Basic
- T1059.006 — Python
- T1070.006 — Timestomp
- T1082 — System Information Discovery
- T1083 — File and Directory Discovery
- T1105 — Ingress Tool Transfer
- T1113 — Screen Capture
- T1543.003 — Windows Service
- T1547.004 — Winlogon Helper DLL
- T1555.003 — Credentials from Web Browsers
- T1559.002 — Dynamic Data Exchange
- T1564.003 — Hidden Window