Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1204.004

T1204.004Malicious Copy and Paste

T1204.004 — Malicious Copy and Paste is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 6 detection use cases covering it and 133 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
6Use cases
133Articles
0Sub-techniques
1Tactic

Use cases covering this technique (6)

Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal exploit · alerting DSΣP [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Internal delivery · alerting DSΣP [LLM] AmnesiaStealer ClickFix loader: macOS shell fetching payload from fake-GitHub / Amnesia C2 host Bespoke delivery · alerting DSΣPCS [LLM] macOS ClickFix: Terminal spawns shell decoding Base64 / curl-pipe payload Bespoke delivery · hunting DSΣPCS [LLM] ClickFix mshta.exe silently executing remote HTA then dropping batch (UAT-11795 initial access) Bespoke delivery · alerting DSΣPDDCS

Articles citing this technique (133)