Detection catalogue

Clipboard-to-Command Delivery Detection

How fake verification pages combine clipboard writes, command tools and social engineering—and how Radar reports the evidence safely.

Clipboard access becomes high priority when it is connected to verification wording and instructions to run concealed content.

The behaviour chain matters

Clipboard APIs are used legitimately by code examples and productivity tools. A command-line reference can also be normal. Concern rises when a verification prompt writes concealed content to the clipboard and directs the visitor to open a system execution tool.

Signals Radar correlates

Safe evidence handling

Radar classifies the capability and destination hosts in memory. Reports describe and redact command-like content rather than reproducing an executable instruction. Downloads and returned payloads are not opened.

False-positive controls

No single generic clipboard call should create a malicious verdict. Severity depends on the surrounding language, delivery mechanics and corroborating signals. Developer documentation and legitimate support content remain important review contexts.

Reference: Microsoft’s ClickFix analysis.

Continue learning

Explore practical response guides.

Browse guidesCheck a link