Technique.View on attack.mitre.org
Adversaries may collect data stored in the clipboard from users copying information within or between applications.
For example, on Windows adversaries can access clipboard data by using clip.exe or Get-Clipboard. Additionally, adversaries may monitor then replace users’ clipboard with their data (e.g., Transmitted Data Manipulation).
macOS and Linux also have commands, such as pbpaste, to grab clipboard contents.
Rules on DetectionCode tagged with T1115.
| Rule | Level | Log source |
|---|---|---|
| Clipboard Access Via OSAScript | medium | macos / process_creation |
| PowerShell Get Clipboard | medium | windows / ps_module |
| PowerShell Get-Clipboard Cmdlet Via CLI | medium | windows / process_creation |
| Clipboard Collection of Image Data with Xclip Tool | low | linux / NULL |
| Clipboard Collection with Xclip Tool | low | linux / process_creation |
| Clipboard Collection with Xclip Tool - Auditd | low | linux / NULL |
| Data Copied To Clipboard Via Clip.EXE | low | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Linux Auditd Clipboard Data Copy | Anomaly | NULL | Linux Auditd Execve |
| Linux Clipboard Data Copy | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Windows ClipBoard Data via Get-ClipBoard | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows Post Exploitation Risk Behavior | Correlation | NULL |
| Used by | Procedure example |
|---|---|
| GroupAPT38 | APT38 used a Trojan called KEYLIME to collect data from the clipboard. |
| GroupAPT39 | APT39 has used tools capable of stealing contents of the clipboard. |
| GroupKimsuky | Kimsuky has the ability to steal data from the clipboard. |
| GroupOilRig | OilRig has used infostealer tools to copy clipboard data. |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla can steal data from the victim’s clipboard. |
| MalwareAstaroth | Astaroth collects information from the clipboard by using the OpenClipboard() and GetClipboardData() libraries. |
| MalwareAttor | Attor has a plugin that collects data stored in the Windows clipboard by using the OpenClipboard and GetClipboardData APIs. |
| MalwareBOOKWORM | BOOKWORM has used its KBLogger.dll module to steal data saved to the clipboard. |
| MalwareCadelspy | Cadelspy has the ability to steal data from the clipboard. |
| MalwareCatchamas | Catchamas steals data stored in the clipboard. |
| MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can capture content from the clipboard. |
| MalwareClambling | Clambling has the ability to capture and store clipboard data. |
| Used by | Procedure example |
|---|---|
| CampaignOperation Wocao | During Operation Wocao, threat actors collected clipboard data in plaintext. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.