KeyBoy

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[KeyBoy](https://attack.mitre.org/software/S0387) is malware that has been used in targeted campaigns against members of the Tibetan Parliament in 2016.(Citation: CitizenLab KeyBoy Nov 2016)(Citation: PWC KeyBoys Feb 2017)

Associated Techniques (18)
ID ATT&CK Tactics
T1001.003 Protocol or Service Impersonation -
T1016 System Network Configuration Discovery -
T1027.013 Encrypted/Encoded File -
T1056.001 Keylogging -
T1059.001 PowerShell -
T1059.003 Windows Command Shell -
T1059.005 Visual Basic -
T1059.006 Python -
T1070.006 Timestomp -
T1082 System Information Discovery -
T1083 File and Directory Discovery -
T1105 Ingress Tool Transfer -
T1113 Screen Capture -
T1543.003 Windows Service -
T1547.004 Winlogon Helper DLL -
Used by Actors (1)
Metadata
ID: 274
Created: 13/01/2026 17:48
Updated: 21/04/2026 04:00