Clipboard Data

T1115

Technique.View on attack.mitre.org

About this technique

Adversaries may collect data stored in the clipboard from users copying information within or between applications.

For example, on Windows adversaries can access clipboard data by using clip.exe or Get-Clipboard. Additionally, adversaries may monitor then replace users’ clipboard with their data (e.g., Transmitted Data Manipulation).

macOS and Linux also have commands, such as pbpaste, to grab clipboard contents.

Detection rules11

Rules on DetectionCode tagged with T1115.

Sigma7

RuleLevelLog source
Clipboard Access Via OSAScriptmediummacos / process_creation
PowerShell Get Clipboardmediumwindows / ps_module
PowerShell Get-Clipboard Cmdlet Via CLImediumwindows / process_creation
Clipboard Collection of Image Data with Xclip Toollowlinux / NULL
Clipboard Collection with Xclip Toollowlinux / process_creation
Clipboard Collection with Xclip Tool - Auditdlowlinux / NULL
Data Copied To Clipboard Via Clip.EXElowwindows / process_creation

Splunk4

RuleTypeRiskData source
Linux Auditd Clipboard Data CopyAnomalyNULLLinux Auditd Execve
Linux Clipboard Data CopyAnomalyNULLSysmon for Linux EventID 1
Windows ClipBoard Data via Get-ClipBoardAnomalyNULLPowershell Script Block Logging 4104
Windows Post Exploitation Risk BehaviorCorrelationNULL

Groups4

Software41

Show 17 more

Campaigns1

Procedure examples46

Groups4

Used byProcedure example
GroupAPT38

APT38 used a Trojan called KEYLIME to collect data from the clipboard.

GroupAPT39

APT39 has used tools capable of stealing contents of the clipboard.

GroupKimsuky

Kimsuky has the ability to steal data from the clipboard.

GroupOilRig

OilRig has used infostealer tools to copy clipboard data.

Software41

Used byProcedure example
MalwareAgent Tesla

Agent Tesla can steal data from the victim’s clipboard.

MalwareAstaroth

Astaroth collects information from the clipboard by using the OpenClipboard() and GetClipboardData() libraries.

MalwareAttor

Attor has a plugin that collects data stored in the Windows clipboard by using the OpenClipboard and GetClipboardData APIs.

MalwareBOOKWORM

BOOKWORM has used its KBLogger.dll module to steal data saved to the clipboard.

MalwareCadelspy

Cadelspy has the ability to steal data from the clipboard.

MalwareCatchamas

Catchamas steals data stored in the clipboard.

MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can capture content from the clipboard.

MalwareClambling

Clambling has the ability to capture and store clipboard data.

View all 41 software examples

Campaigns1

Used byProcedure example
CampaignOperation Wocao

During Operation Wocao, threat actors collected clipboard data in plaintext.

References5

  1. CISA_AA21_200B Open source
    CISA. (2021, August 20). Alert (AA21-200B) Chinese State-Sponsored Cyber Operations: Observed TTPs. Retrieved June 21, 2022.
  2. MSDN Clipboard Open source
    Microsoft. (n.d.). About the Clipboard. Retrieved March 29, 2016.
  3. Operating with EmPyre Open source
    rvrsh3ll. (2016, May 18). Operating with EmPyre. Retrieved July 12, 2017.
  4. clip_win_server Open source
    Microsoft, JasonGerend, et al. (2023, February 3). clip. Retrieved June 21, 2022.
  5. mining_ruby_reversinglabs Open source
    Maljic, T. (2020, April 16). Mining for malicious Ruby gems. Retrieved October 15, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.