Malicious Copy and Paste

T1204.004

Sub-technique of T1204 User Execution.View on attack.mitre.org

About this technique

An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions—such as prompts to fix errors or complete CAPTCHAs—that instead instruct the user to copy and paste malicious code.

Malicious websites, such as those used in Drive-by Compromise, may present fake error messages or CAPTCHA prompts that instruct users to open a terminal or the Windows Run Dialog box and execute an arbitrary command. These commands may be obfuscated using encoding or other techniques to conceal malicious intent. Once executed, the adversary will typically be able to establish a foothold on the victim's machine.

Adversaries may also leverage phishing emails for this purpose. When a user attempts to open an attachment, they may be presented with a fake error and offered a malicious command to paste as a solution, consistent with the "ClickFix" strategy.

Tricking a user into executing a command themselves may help to bypass email filtering, browser sandboxing, or other mitigations designed to protect users against malicious downloaded files.

Detection rules7

Rules on DetectionCode tagged with T1204.004.

Sigma7

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software2

Campaigns0

None recorded.

Procedure examples5

Groups3

Used byProcedure example
GroupContagious Interview

Contagious Interview has leveraged ClickFix type tactics enticing victims to copy and paste malicious code.

GroupKimsuky

Kimsuky has leveraged ClickFix type tactics enticing victims to copy and paste malicious code.

GroupMuddyWater

MuddyWater has leveraged ClickFix type tactics enticing victims to copy and paste malicious PowerShell code.

Software2

Used byProcedure example
MalwareHavoc

The Havoc infection chain has been initiated via ClickFix lures in phishing emails.

MalwareKali365

Kali365 has dynamically generated legitimate device codes that displays on the victims screen alongside instructions to copy and paste the device code to initiate and complete a successful authentication process.

References6

  1. AhnLab LummaC2 2025 Open source
    AhnLab SEcurity intelligence Center. (2025, January 8). Infostealer LummaC2 Spreading Through Fake CAPTCHA Verification Page. Retrieved April 23, 2025.
  2. AhnLab Malicioys Copy Paste 2024 Open source
    AhnLab SEcurity intelligence Center. (2024, May 23). Warning Against Phishing Emails Prompting Execution of Commands via Paste (CTRL+V). Retrieved April 23, 2025.
  3. CloudSEK Lumma Stealer 2024 Open source
    CloudSEK TRIAD. (2024, September 19). Unmasking the Danger: Lumma Stealer Malware Exploits Fake CAPTCHA Pages. Retrieved March 18, 2025.
  4. Proofpoint ClickFix 2024 Open source
    Tommy Madjar, Selena Larson and The Proofpoint Threat Research Team. (2024, November 18). Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape. Retrieved March 18, 2025.
  5. Reliaquest CAPTCHA 2024 Open source
    Alex Capraro. (2024, December 17). Using CAPTCHA for Compromise: Hackers Flip the Script. Retrieved March 18, 2025.
  6. Sekoia ClickFake 2025 Open source
    Amaury G., Coline Chavane, Felix Aimé and Sekoia TDR. (2025, March 31). From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic. Retrieved April 1, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.