ATT&CK · T1115
Clipboard Data
Tactics: collection
About
Adversaries may collect data stored in the clipboard from users copying information within or between applications. For example, on Windows adversaries can access clipboard data by using <code>clip.exe</code> or <code>Get-Clipboard</code>. Additionally, adversaries may monitor then replace users’ clipboard with their data (e.g., Transmitted Data Manipulation). macOS and Linux also have commands, such as <code>pbpaste</code>, to grab clipboard contents.
Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗
Used by actors
4 known groups
Software
41 malware/tools implement this
TinyZBotJHUHUGITCosmicDukeRTMHelminthROKRATKoadicRunningRATVERMINCatchamasMacSpyjRATZeus PandaAgent TeslaRemcosDarkCometKONNIEmpireAstarothRemexiFlawedAmmyyMacheteAttorCadelspyMetamorfoTajMahalMelcozGrandoreiroExplosiveMarkiRATClamblingSILENTTRINITYDarkTortillaDarkGateMispaduMgBotCHIMNEYSWEEPXLoaderBOOKWORMPAKLOGInvisibleFerret
Corpus indicators tagged with this technique
155 indicators in the corpus carry T1115.
Showing the top 30 by severity of 155.