# T1115 Clipboard Data

> As of 2026-10-05, T1115 (Clipboard Data) appears in 163 tracked threats, first reported 2026-01-14 and most recently 2026-08-21, with linked actors including APT38, Contagious Interview, Lazarus Group; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 163 (16 critical, 140 high, 7 medium)
- **First seen:** 2026-01-14
- **Last seen:** 2026-08-21
- **Threat actors:** 58
- **Detection rules:** 128 (counts only; Blue tier and above)

## Key facts

- **ID:** T1115
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1115/

## Activity timeline

T1115 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-08-21. The busiest month was 2026-07 with 68 reports, and 163 of the 163 threats were reported in the twelve months to 2026-08.

## How adversaries use it

T1115 Clipboard Data is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 163 of 2623 tracked threats (6.2%) to it; by severity that is 16 critical, 140 high, 7 medium.

Threats that use T1115 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (139 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (138 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (131 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (113 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (111 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

58 tracked threat actors appear in the threats that use T1115; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (12), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (9), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (8), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (8), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (8).

## Data sources

Telemetry that can reveal T1115, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 12
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 9
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 8
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 8
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 8
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 7
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 6
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 6
- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 4
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 3
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 3
- [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) — 3

## Tracked threats

The 30 most recent of 163 tracked threats that use T1115.

- [Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet](https://intel.threadlinqs.com/threat/TL-2026-2100) — high — 2026-08-21
- [Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targets](https://intel.threadlinqs.com/threat/TL-2026-2016) — high — 2026-08-14
- [Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRig](https://intel.threadlinqs.com/threat/TL-2026-1979) — high — 2026-08-10
- [Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across…](https://intel.threadlinqs.com/threat/TL-2026-1816) — high — 2026-08-02
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…](https://intel.threadlinqs.com/threat/TL-2026-1792) — high — 2026-07-31
- [OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-1786) — high — 2026-07-31
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [Adform Ad-Tech Platform Compromised: Supply-Chain Injection Serves Clipboard Crypto Stealer via…](https://intel.threadlinqs.com/threat/TL-2026-1775) — high — 2026-07-30
- [Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…](https://intel.threadlinqs.com/threat/TL-2026-1805) — critical — 2026-07-28
- [Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan](https://intel.threadlinqs.com/threat/TL-2026-1746) — critical — 2026-07-28
- [AutoIT Payload Injector Delivers VIPKeylogger via Phishing/RAR Chain into charmap.exe](https://intel.threadlinqs.com/threat/TL-2026-1740) — medium — 2026-07-28
- [Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience](https://intel.threadlinqs.com/threat/TL-2026-1738) — high — 2026-07-28
- [MedusaHVNC — Hidden Virtual Desktop RAT with AMSI/ETW Bypass and Multi-Browser Session Hijacking](https://intel.threadlinqs.com/threat/TL-2026-1733) — high — 2026-07-27
- [MedusaHVNC: Malware-as-a-Service RAT Uses Hidden Desktop (hVNC) to Hijack Live Browser Sessions and Steal…](https://intel.threadlinqs.com/threat/TL-2026-1723) — high — 2026-07-27
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — high — 2026-07-27
- [BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls](https://intel.threadlinqs.com/threat/TL-2026-1720) — high — 2026-07-27
- [BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-1719) — high — 2026-07-27
- [Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ Applications](https://intel.threadlinqs.com/threat/TL-2026-1698) — high — 2026-07-25
- [Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar…](https://intel.threadlinqs.com/threat/TL-2026-1693) — high — 2026-07-25
- [Critical FreeRDP Clipboard Virtual Channel Heap Buffer Overflow (GHSA-cj9v-h4hq-29jr, CVSS 9.4)](https://intel.threadlinqs.com/threat/TL-2026-1689) — critical — 2026-07-25
- [BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…](https://intel.threadlinqs.com/threat/TL-2026-1678) — high — 2026-07-24
- [ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to…](https://intel.threadlinqs.com/threat/TL-2026-1664) — high — 2026-07-24
- [Red Canary Intelligence Insights July 2026: ClearFake Leads Third Straight Month Amid CastleLoader Debut and…](https://intel.threadlinqs.com/threat/TL-2026-1658) — medium — 2026-07-23
- [GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous…](https://intel.threadlinqs.com/threat/TL-2026-1610) — high — 2026-07-22
- [SnappyClient RAT — C++ C2 Implant Delivered via HijackLoader (Operation Turb00 Part 3)](https://intel.threadlinqs.com/threat/TL-2026-1589) — high — 2026-07-21
- [OTTERCOOKIE Malware Hidden in SVG Flag Images Backdoors Developers via Fake Coding Tests (Contagious…](https://intel.threadlinqs.com/threat/TL-2026-1581) — high — 2026-07-20
- [North Korean Contagious Interview Campaign Deploys OtterCookie via SVG Steganography to Steal Developer…](https://intel.threadlinqs.com/threat/TL-2026-1571) — high — 2026-07-20
- [ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stage](https://intel.threadlinqs.com/threat/TL-2026-1558) — high — 2026-07-20

## Related CVEs

CVEs referenced by the tracked threats that use T1115, most frequent first.

- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2017-11882](https://intel.threadlinqs.com/cve/CVE-2017-11882)
- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2017-8570](https://intel.threadlinqs.com/cve/CVE-2017-8570)
- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2021-30952](https://intel.threadlinqs.com/cve/CVE-2021-30952)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2022-32917](https://intel.threadlinqs.com/cve/CVE-2022-32917)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-42856](https://intel.threadlinqs.com/cve/CVE-2022-42856)
- [CVE-2022-46689](https://intel.threadlinqs.com/cve/CVE-2022-46689)
- [CVE-2023-23514](https://intel.threadlinqs.com/cve/CVE-2023-23514)
- [CVE-2023-23529](https://intel.threadlinqs.com/cve/CVE-2023-23529)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-28204](https://intel.threadlinqs.com/cve/CVE-2023-28204)
- [CVE-2023-28206](https://intel.threadlinqs.com/cve/CVE-2023-28206)
- [CVE-2023-29059](https://intel.threadlinqs.com/cve/CVE-2023-29059)
- [CVE-2023-32373](https://intel.threadlinqs.com/cve/CVE-2023-32373)
- [CVE-2023-32409](https://intel.threadlinqs.com/cve/CVE-2023-32409)
- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434)
- [CVE-2023-32435](https://intel.threadlinqs.com/cve/CVE-2023-32435)
- [CVE-2023-37450](https://intel.threadlinqs.com/cve/CVE-2023-37450)
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)
- [CVE-2023-41974](https://intel.threadlinqs.com/cve/CVE-2023-41974)
- [CVE-2023-41990](https://intel.threadlinqs.com/cve/CVE-2023-41990)

## Detection coverage

Threadlinqs maintains 128 detection rules mapped to T1115 (SPL 24, KQL 53, Sigma 51). Rule content is available to Blue tier accounts and above; this page shows counts only.

128 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1115
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
