.. / Atbroker.exe
Star

Helper binary for Assistive Technology (AT)


Paths:


Resources:
http://www.hexacorn.com/blog/2016/07/22/beyond-good-ol-run-key-part-42/

Acknowledgement:
Adam - @hexacorn


Detection:
Changes to HKCU\Software\Microsoft\Windows NT\CurrentVersion\Accessibility\Configuration
Changes to HKCU\Software\Microsoft\Windows NT\CurrentVersion\Accessibility\ATs
Unknown AT starting C:\Windows\System32\ATBroker.exe /start malware



Execute

Start a registered Assistive Technology (AT).
ATBroker.exe /start malware
Usecase:Executes code defined in registry for a new AT. Modifications must be made to the system registry to either register or modify an existing Assistibe Technology (AT) service entry.
Privileges required:User
OS:Windows 8, Windows 8.1, Windows 10
Mitre:T1218