Security expert Dylan Ayrey has devised a new attack technique dubbed Pastejacking attack that leverages on the victims clipboard. Attackers can write malicious code in the clipboard and then fool victims into executing terminal commands. The new attack scenario sees victims receiving a phishing e-mail purporting to be from tech support could trick them into dropping a message into a terminal window and executing it. In reality, the attacker is exploiting the machine clipboard to launch the attack. Experts also provided also more sophisticated payloads, like the following one that will create a file in the user’s home directory and clean the terminal out.”]
Source: https://securityaffairs.co/wordpress/47665/hacking/pastejack-attack.html

