#T1115 Clipboard Data
Technique
- Tactics: Collection
- Description:
Adversaries may collect data stored in the clipboard from users copying information within or between applications.
For example, on Windows adversaries can access clipboard data by using <code>clip.exe</code> or <code>Get-Clipboard</code>.(Citation: MSDN Clipboard)(Citation: clip_win_server)(Citation: CISA_AA21_200B) Additionally, adversaries may monitor then replace users’ clipboard with their data (e.g., [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002)).(Citation: mining_ruby_reversinglabs)
macOS and Linux also have commands, such as <code>pbpaste</code>, to grab clipboard contents.(Citation: Operating with EmPyre)
- First Seen: APT38 • 2019-01-29
-
20
Tagged Reports
-
17
Unique Authors
-
2,676
Active Days
Tagged Reports
2026-04-17
Break Glass Intelligence
2025-11-26
Socket
2025-08-25
Bloo
2025-02-20
ESET
2024-07-19
Cyfirma