Clipboard Data

Adversaries may collect data stored in the clipboard from users copying information within or between applications.

In Windows, Applications can access clipboard data by using the Windows API.[1] OSX provides a native command, pbpaste, to grab clipboard contents.[2]

ID: T1115
Sub-techniques:  No sub-techniques
Tactic: Collection
Platforms: Linux, Windows, macOS
Version: 1.1
Created: 31 May 2017
Last Modified: 23 April 2020

Procedure Examples

ID Name Description
S0331 Agent Tesla

Agent Tesla can steal data from the victim’s clipboard.[3][4][5][6]

G0082 APT38

APT38 used a Trojan called KEYLIME to collect data from the clipboard.[7]

G0087 APT39

APT39 has used tools capable of stealing contents of the clipboard.[8]

S0373 Astaroth

Astaroth collects information from the clipboard by using the OpenClipboard() and GetClipboardData() libraries. [9]

S0438 Attor

Attor has a plugin that collects data stored in the Windows clipboard by using the OpenClipboard and GetClipboardData APIs.[10]

S0454 Cadelspy

Cadelspy has the ability to steal data from the clipboard.[11]

S0261 Catchamas

Catchamas steals data stored in the clipboard.[12]

S0660 Clambling

Clambling has the ability to capture and store clipboard data.[13][14]

S0050 CosmicDuke

CosmicDuke copies and exfiltrates the clipboard contents every 30 seconds.[15]

S0334 DarkComet

DarkComet can steal data from the clipboard.[16]

S0363 Empire

Empire can harvest clipboard data on both Windows and macOS systems.[17]

S0569 Explosive

Explosive has a function to use the OpenClipboard wrapper.[18]

S0531 Grandoreiro

Grandoreiro can capture clipboard data from a compromised host.[19]

S0170 Helminth

The executable version of Helminth has a module to log clipboard contents.[20]


A JHUHUGIT variant accesses a screenshot saved in the clipboard and converts it to a JPG image.[21]

S0283 jRAT

jRAT can capture clipboard data.[22]

S0250 Koadic

Koadic can retrieve the current content of the user clipboard.[23]


KONNI had a feature to steal data from the clipboard.[24]

S0409 Machete

Machete hijacks the clipboard data by creating an overlapped window that listens to keyboard events.[25][26]

S0282 MacSpy

MacSpy can steal clipboard contents.[27]

S0652 MarkiRAT

MarkiRAT can capture clipboard content.[28]

S0530 Melcoz

Melcoz can monitor content saved to the clipboard.[29]

S0455 Metamorfo

Metamorfo has a function to hijack data from the clipboard by monitoring the contents of the clipboard and replacing the cryptocurrency wallet with the attacker's.[30][31]

G0116 Operation Wocao

Operation Wocao has collected clipboard data in plaintext.[32]

S0332 Remcos

Remcos steals and modifies data from the clipboard.[33]

S0375 Remexi

Remexi collects text from the clipboard.[34]


ROKRAT can extract clipboard data from a compromised host.[35]

S0148 RTM

RTM collects data from the clipboard.[36][37]

S0253 RunningRAT

RunningRAT contains code to open and copy data from the clipboard.[38]

S0467 TajMahal

TajMahal has the ability to steal data from the clipboard of an infected host.[39]

S0004 TinyZBot

TinyZBot contains functionality to collect information from the clipboard.[40]


VERMIN collects data stored in the clipboard.[41]

S0330 Zeus Panda

Zeus Panda can hook GetClipboardData function to watch for clipboard pastes to collect.[42]


This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.


ID Data Source Data Component Detects
DS0017 Command Command Execution

Monitor executed commands and arguments to collect data stored in the clipboard from users copying information within or between applications.

DS0009 Process OS API Execution

Monitor API calls that could collect data stored in the clipboard from users copying information within or between applications.


