T1204.004Malicious Copy and Paste
T1204.004 — Malicious Copy and Paste is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 6 detection use cases covering it and 133 threat-intel articles citing it.
Execution
6Use cases
133Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1204 · User Execution
Use cases covering this technique (6)
Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) [LLM] AmnesiaStealer ClickFix loader: macOS shell fetching payload from fake-GitHub / Amnesia C2 host [LLM] macOS ClickFix: Terminal spawns shell decoding Base64 / curl-pipe payload [LLM] ClickFix mshta.exe silently executing remote HTA then dropping batch (UAT-11795 initial access)Articles citing this technique (133)
crit Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware art-28
crit Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner art-38
high Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware art-40
high Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers art-44
crit APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit art-48
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories art-51
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55
high OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning art-69
high DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt art-82
crit A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices art-85
crit Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo art-86
crit Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers art-88
high Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets art-90
crit The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications art-96
crit Begun, the Patch Wars have art-253
crit ESET Threat Report H1 2026 art-312
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-408
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-468
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-592
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-673
crit ESET Threat Report H2 2025 art-762
high Ethical hacking techniques art-1721
high Ethical Hacking: Top Tools art-1725
high Snyk joins OpenSSF: Tackling open source supply chain security with a developer-first approach art-3089
crit XSS Attacks: The Next Wave art-3664