# T1414 Clipboard Data

> As of 2026-10-05, T1414 (Clipboard Data) appears in 16 tracked threats, first reported 2026-02-24 and most recently 2026-09-20, with linked actors including MoYu Group; it most often appears alongside T1426 (System Information Discovery).

- **Tracked threats:** 16 (4 critical, 10 high, 2 medium)
- **First seen:** 2026-02-24
- **Last seen:** 2026-09-20
- **Threat actors:** 1
- **Detection rules:** 8 (counts only; Blue tier and above)

## Key facts

- **ID:** T1414
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection (Mobile), Credential Access (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1414/

## Activity timeline

T1414 first appeared in tracked threats on 2026-02-24 and was most recently reported on 2026-09-20. The busiest month was 2026-07 with 7 reports, and 16 of the 16 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1414 Clipboard Data is catalogued by MITRE ATT&CK under the Collection (Mobile) and Credential Access (Mobile) tactics in the Mobile matrix. Threadlinqs maps 16 of 2623 tracked threats (0.6%) to it; by severity that is 4 critical, 10 high, 2 medium.

Threats that use T1414 most often also use [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (14 threats), [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (13 threats), [T1437 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1437) (11 threats), [T1418 Software Discovery](https://intel.threadlinqs.com/technique/T1418) (10 threats), [T1417 Input Capture](https://intel.threadlinqs.com/technique/T1417) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use T1414; the most frequent are [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1414.

- [M1006 Use Recent OS Version](https://attack.mitre.org/mitigations/M1006/)

## Threat actors using it

- [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) — 1

## Tracked threats

16 tracked threats use T1414.

- [FomoPeek iOS App Store Poisoning: Kernel Exploit Framework Steals Crypto Private Keys via Keychain Decryption](https://intel.threadlinqs.com/threat/TL-2026-2591) — critical — 2026-09-20
- [JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet](https://intel.threadlinqs.com/threat/TL-2026-2111) — high — 2026-08-22
- [Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-1841) — high — 2026-08-03
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1667) — medium — 2026-07-24
- [Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet…](https://intel.threadlinqs.com/threat/TL-2026-1394) — medium — 2026-07-16
- [Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking…](https://intel.threadlinqs.com/threat/TL-2026-1225) — high — 2026-07-11
- [Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader](https://intel.threadlinqs.com/threat/TL-2026-1195) — high — 2026-07-10
- [Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee](https://intel.threadlinqs.com/threat/TL-2026-1110) — critical — 2026-07-05
- [European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…](https://intel.threadlinqs.com/threat/TL-2026-1099) — critical — 2026-07-03
- [Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…](https://intel.threadlinqs.com/threat/TL-2026-1098) — high — 2026-07-03
- [Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands](https://intel.threadlinqs.com/threat/TL-2026-0826) — high — 2026-06-16
- [BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…](https://intel.threadlinqs.com/threat/TL-2026-0600) — high — 2026-05-27
- [OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and…](https://intel.threadlinqs.com/threat/TL-2026-0598) — critical — 2026-05-27
- [TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…](https://intel.threadlinqs.com/threat/TL-2026-0494) — high — 2026-05-11
- [SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolution](https://intel.threadlinqs.com/threat/TL-2026-0142) — high — 2026-02-24

## Detection coverage

Threadlinqs maintains 8 detection rules mapped to T1414 (KQL 6, Sigma 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

8 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1414
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
