FORENSIA

ATT&CK · T1115

Clipboard Data

Tactics: collection

About

Adversaries may collect data stored in the clipboard from users copying information within or between applications. For example, on Windows adversaries can access clipboard data by using <code>clip.exe</code> or <code>Get-Clipboard</code>. Additionally, adversaries may monitor then replace users’ clipboard with their data (e.g., Transmitted Data Manipulation). macOS and Linux also have commands, such as <code>pbpaste</code>, to grab clipboard contents.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

4 known groups

Software

41 malware/tools implement this

TinyZBotJHUHUGITCosmicDukeRTMHelminthROKRATKoadicRunningRATVERMINCatchamasMacSpyjRATZeus PandaAgent TeslaRemcosDarkCometKONNIEmpireAstarothRemexiFlawedAmmyyMacheteAttorCadelspyMetamorfoTajMahalMelcozGrandoreiroExplosiveMarkiRATClamblingSILENTTRINITYDarkTortillaDarkGateMispaduMgBotCHIMNEYSWEEPXLoaderBOOKWORMPAKLOGInvisibleFerret

Corpus indicators tagged with this technique

155 indicators in the corpus carry T1115.

IndicatorTypeFamilySevSrc
1e77992666acbbfa0d01fcefa9cc8fbdac291e0681b35745be27c6dfb159a375sha256phishing801
21b24f7ee1f6bdbbb670f0394d66009ee0daa8ced57048298da715e88f7a7cddsha256phishing801
18fd38988d58dd930f5992d448cc09a9400c1eafba76b820b9a83239ac48cf4esha256phishing801
19ac18a50abb48dc0ea9524850acfaec49359e6b3bcc67c6193c2d56da812c71sha256phishing801
f0ea4c47bc8fec96770d023f1025bcb3hash803
d4eb4ff02df659fdeec17d36b77084627469623bb3c7d16383d257404b52d1c3sha256phishing801
638636692e3eef6c83dbca784a40fb7b6ac95b76d6551a2fbdfebc11588ad8ffsha256supply_chain801
7386252b9a86e5357e6aa884326720abf015465a2567e75717830b6688ef05ccsha256supply_chain801
3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5sha256phishing801
670384fafb23140d96f2f8fe04a13fc8cc8e2a6e5e8c973e39b58d103c5fea92sha256phishing801
b3b63970833b3379ecec2d3ef8fea328fef8dd1c1574b1bcdfebad5bdce9280csha256supply_chain801
72fc06a8b03720f4a64744eecd5b3f658ad880bdb327c0c465c7bdc66b14a8d2sha256supply_chain801
d6b6eb84b0718cbd02eea586637679b4d77bb34fhash803
e6e78eb2e9bd41a4bc62f7ad54d095ea9813864bebe37172ae30a1afa631fe14sha256phishing801
2fe9c41901045013ba28ccb9af5870f9aef4f1ffd1e717cd5e0189ffdbe7fca2sha256supply_chain801
606966a9ec33765baedf63331595d1168f2a596fhash803
11f01e8296a074e6e3b23e9413c51f205d4b6a14146fb4d95bec291d768a9071sha256supply_chain801
fbbdf4bc490ad7b28953630c1707aa68b89d319b9b735f3d8563320b81b21a97sha256supply_chain801
bbe05d2f2487ed09e1062111fd448822364a44a7hashwallet_compromise801
ecdc8fade561a75d68235859ad8b1fe131db2c458b4894268e38e90ecab1c47fhash802
f48bf08687948ead049686cdee0e92ddhash803
d7d43e8e8f03afdcaaba85622daf24ced944e7ca4d03ac124fc325d0bb6e3d66sha256supply_chain801
b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173sha256phishing801
07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841sha256phishing801
e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95sha256phishing801
43dc5b1d4c73d5ed9f4f7f561830079896eeb533a7c21bc577e4e267d5a3aa56sha256supply_chain801
03b51af0a04467cebfa235199db4c02ehashwallet_compromise801
a3d2ea3aa5850ecac5e75b0cc1467bda57dbb776hash803
fadbb8061715128bebecf7bc59132b6bb04fe8cc39b965aa5b8722dffe28d7e7sha256phishing801
48723a33bab89f174750576f9a62da35b3b9e5ac31a5a8f1ce9859a1b35bf8b8sha256phishing801

Showing the top 30 by severity of 155.