Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1204.004

T1204.004Malicious Copy and Paste

T1204.004 — Malicious Copy and Paste is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 7 detection use cases covering it and 117 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
7Use cases
117Articles
0Sub-techniques
1Tactic

Use cases covering this technique (7)

Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal exploit · alerting DSΣP [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Internal delivery · alerting DSΣP [LLM] ClickFix RunMRU entry launching rundll32 against WebDAV GUID share (ACR Stealer) Bespoke delivery · alerting DSΣPDDCS [LLM] MSHTA remote HTA launched by explorer→powershell chain (ACR Stealer fileless campaign) Bespoke delivery · alerting DSΣPDDCS [LLM] ClickFix mshta.exe silently executing remote HTA then dropping batch (UAT-11795 initial access) Bespoke delivery · alerting DSΣPDDCS [LLM] OpenClaw paste-site (rentry.co/glot.io) curl-pipe-bash semantic-hijack dropper Bespoke delivery · hunting DSΣPCS

Articles citing this technique (117)