T1113 - Screen Capture
Tactics:
Collection
Collection
Platforms:
Linux Windows macOS
Linux Windows macOS
Detection:
Not specified
Not specified
Description:
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware)
Used by Actors (18)
APT28
Nation-state
Nation-state
FIN7
Criminal
Criminal
OilRig
Nation-state
Nation-state
Gamaredon Group
Unknown
Unknown
Kimsuky
Nation-state
Nation-state
MuddyWater
Nation-state
Nation-state
Dark Caracal
Unknown
Unknown
APT39
Unknown
Unknown
Group5
Unknown
Unknown
GOLD SOUTHFIELD
Unknown
Unknown
APT42
Nation-state
Nation-state
Volt Typhoon
Unknown
Unknown
MoustachedBouncer
Nation-state
Nation-state
Winter Vivern
Unknown
Unknown
Dragonfly
Unknown
Unknown
Silence
Unknown
Unknown
Magic Hound
Unknown
Unknown
BRONZE BUTLER
Unknown
Unknown
Malware (20)
Metadata
| MITRE ID: | T1113 |
| STIX ID: | attack-pattern--0259baeb-9f63-... |
| Platforms: | Linux, Windows, macOS |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 16:00 |