MITRE ATT&CK Technique
T1113Screen Capture
- First Reported
- Aug 3, 2026
- Latest Reported
- Oct 1, 2026
Official Description
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware)
- Tactics
- Collection
- Platforms
- Linux, macOS, Windows
- MITRE Version
- 1.1
- Last Modified
- May 12, 2026
Reported Context (7)
- Cited open-source reporting identifies screenshot collection among Remus capabilities. CIS Links SLTT Remus C2 Traffic to Three Malware Delivery Chains
- The article states that Remcos RAT can capture the infected system's screen. Phishing Emails Use Fake Purchase Requests to Deliver Remcos RAT
- The article identifies screen capture as one of Remcos RAT's information-collection functions. Phishing Quote Requests Deliver Remcos RAT via Obfuscated PowerShell
- A Kothamine build hosted on GitHub included a screenshot command. Kothamine RAT Uses Tailscale’s Tailcat for Encrypted Command-and-Control
- The analyzed StreamRat sample can capture the compromised Android device's screen. Fake National Health Service Site Delivers StreamRat on Android and XWorm on Windows
CVE (1)
Malware (8)
Threat Actors (4)
MITRE ATT&CK (41)
Vendors (4)
Products (21)
Tools (17)
Industries (4)
Countries (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.