# T1204.004 Malicious Copy and Paste

> As of 2026-10-05, T1204.004 (Malicious Copy and Paste) appears in 59 tracked threats, first reported 2026-05-06 and most recently 2026-10-03, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 59 (4 critical, 52 high, 3 medium)
- **First seen:** 2026-05-06
- **Last seen:** 2026-10-03
- **Threat actors:** 28
- **Detection rules:** 175 (counts only; Blue tier and above)

## Key facts

- **ID:** T1204.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Parent:** T1204
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1204/004/

## Activity timeline

T1204.004 first appeared in tracked threats on 2026-05-06 and was most recently reported on 2026-10-03. The busiest month was 2026-08 with 18 reports, and 59 of the 59 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1204.004 Malicious Copy and Paste is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix, as a sub-technique of [T1204 User Execution](https://intel.threadlinqs.com/technique/T1204). Threadlinqs maps 59 of 2623 tracked threats (2.2%) to it; by severity that is 4 critical, 52 high, 3 medium.

Threats that use T1204.004 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (45 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (38 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (37 threats), [T1555.003 Credentials from Web Browsers](https://intel.threadlinqs.com/technique/T1555.003) (37 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (34 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

28 tracked threat actors appear in the threats that use T1204.004; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (4), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (3), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (3), [Woodgnat](https://intel.threadlinqs.com/actor/Woodgnat) (3), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (2).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1204.004.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)

## Data sources

Telemetry that can reveal T1204.004, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation
- Network Traffic — Network Connection Creation, Network Traffic Content
- Process — Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 3
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 3
- [Woodgnat](https://intel.threadlinqs.com/actor/Woodgnat) — 3
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 2
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1

## Tracked threats

The 30 most recent of 59 tracked threats that use T1204.004.

- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…](https://intel.threadlinqs.com/threat/TL-2026-2858) — high — 2026-10-03
- [Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)](https://intel.threadlinqs.com/threat/TL-2026-2916) — high — 2026-10-02
- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer](https://intel.threadlinqs.com/threat/TL-2026-2699) — high — 2026-09-27
- [Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…](https://intel.threadlinqs.com/threat/TL-2026-2685) — high — 2026-09-27
- [Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2664) — high — 2026-09-26
- [Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts](https://intel.threadlinqs.com/threat/TL-2026-2622) — high — 2026-09-23
- [Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)](https://intel.threadlinqs.com/threat/TL-2026-2603) — high — 2026-09-21
- [EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials](https://intel.threadlinqs.com/threat/TL-2026-2600) — critical — 2026-09-21
- [ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…](https://intel.threadlinqs.com/threat/TL-2026-2589) — high — 2026-09-20
- [DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patients](https://intel.threadlinqs.com/threat/TL-2026-2328) — high — 2026-09-04
- [Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channel](https://intel.threadlinqs.com/threat/TL-2026-2311) — high — 2026-09-03
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2273) — high — 2026-09-01
- [TerminalFix Campaign Deploys Custom Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA and Multistage…](https://intel.threadlinqs.com/threat/TL-2026-2265) — critical — 2026-08-31
- [Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usage](https://intel.threadlinqs.com/threat/TL-2026-2234) — medium — 2026-08-30
- [Hundreds of WordPress Sites Hijacked via Malicious Plugins to Deploy Amatera Stealer through EtherHiding and…](https://intel.threadlinqs.com/threat/TL-2026-2214) — high — 2026-08-29
- [Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-2203) — high — 2026-08-29
- [ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked…](https://intel.threadlinqs.com/threat/TL-2026-2199) — high — 2026-08-29
- [Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware](https://intel.threadlinqs.com/threat/TL-2026-2197) — high — 2026-08-29
- [Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake…](https://intel.threadlinqs.com/threat/TL-2026-2280) — medium — 2026-08-28
- [Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Theft](https://intel.threadlinqs.com/threat/TL-2026-2229) — high — 2026-08-28
- [ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer](https://intel.threadlinqs.com/threat/TL-2026-2142) — high — 2026-08-25
- [Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers…](https://intel.threadlinqs.com/threat/TL-2026-2120) — high — 2026-08-23
- [Go-Based macOS Stealer Uses ClickFix Lures to Drain Cryptocurrency Wallets (Aeza Group Infrastructure)](https://intel.threadlinqs.com/threat/TL-2026-2066) — high — 2026-08-18
- [Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation…](https://intel.threadlinqs.com/threat/TL-2026-2058) — high — 2026-08-18
- [StopAndProtect: Compromised WordPress Sites Used as Malware Distribution Infrastructure for Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-2057) — high — 2026-08-18
- [AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control](https://intel.threadlinqs.com/threat/TL-2026-2029) — high — 2026-08-16
- [ClickFix Attacks Deliver Go-Based macOS Infostealer Targeting Crypto Wallets and Keychain Data](https://intel.threadlinqs.com/threat/TL-2026-1936) — high — 2026-08-07
- [Ransomware Moves up the Org Chart: Managers Are Prime Targets (Zscaler ThreatLabz, 351 Victims / 334…](https://intel.threadlinqs.com/threat/TL-2026-2897) — high — 2026-08-06
- [QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day…](https://intel.threadlinqs.com/threat/TL-2026-2893) — high — 2026-08-06

## Related CVEs

CVEs referenced by the tracked threats that use T1204.004, most frequent first.

- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2022-2586](https://intel.threadlinqs.com/cve/CVE-2022-2586)
- [CVE-2023-0386](https://intel.threadlinqs.com/cve/CVE-2023-0386)
- [CVE-2023-20598](https://intel.threadlinqs.com/cve/CVE-2023-20598)
- [CVE-2023-44487](https://intel.threadlinqs.com/cve/CVE-2023-44487)
- [CVE-2023-4911](https://intel.threadlinqs.com/cve/CVE-2023-4911)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)

## Detection coverage

Threadlinqs maintains 175 detection rules mapped to T1204.004 (SPL 68, KQL 52, Sigma 55). Rule content is available to Blue tier accounts and above; this page shows counts only.

175 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1204 User Execution](https://intel.threadlinqs.com/technique/T1204) — 571 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1204.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
