Activity timeline
T1204.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 18 reports, and 59 of the 59 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1204.004 Malicious Copy and Paste is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of T1204 User Execution. Threadlinqs maps 59 of 2623 tracked threats (2.2%) to it; by severity that is 4 critical, 52 high, 3 medium.
Threats that use T1204.004 most often also use T1071.001 Web Protocols (45 threats), T1027 Obfuscated Files or Information (38 threats), T1082 System Information Discovery (37 threats), T1555.003 Credentials from Web Browsers (37 threats), T1059.001 PowerShell (34 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
28 tracked threat actors appear in the threats that use T1204.004; the most frequent are APT38 (4), Sapphire Sleet (3), Stardust Chollima (3), Woodgnat (3), Andariel (2).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1204.004.
Data sources
Telemetry that can reveal T1204.004, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation
- Network Traffic — Network Connection Creation, Network Traffic Content
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 59 tracked threats that use T1204.004.
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…high
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)high
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealerhigh
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…high
- Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…high
- Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Promptshigh
- Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)high
- EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentialscritical
- ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…high
- DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patientshigh
- Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channelhigh
- EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign…high
- TerminalFix Campaign Deploys Custom Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA and Multistage…critical
- Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usagemedium
- Hundreds of WordPress Sites Hijacked via Malicious Plugins to Deploy Amatera Stealer through EtherHiding and…high
- Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL Sideloadinghigh
- ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked…high
- Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malwarehigh
- Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake…medium
- Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Thefthigh
- ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealerhigh
- Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers…high
- Go-Based macOS Stealer Uses ClickFix Lures to Drain Cryptocurrency Wallets (Aeza Group Infrastructure)high
- Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation…high
- StopAndProtect: Compromised WordPress Sites Used as Malware Distribution Infrastructure for Ransomware…high
- AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Controlhigh
- ClickFix Attacks Deliver Go-Based macOS Infostealer Targeting Crypto Wallets and Keychain Datahigh
- Ransomware Moves up the Org Chart: Managers Are Prime Targets (Zscaler ThreatLabz, 351 Victims / 334…high
- QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day…high
Detection coverage
Threadlinqs maintains 175 detection rules mapped to T1204.004 (SPL 68, KQL 52, Sigma 55). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1204 User Execution — 571 tracked threats at the technique level.