Accessibility Features

T1546.008

Sub-technique of T1546 Event Triggered Execution.View on attack.mitre.org

About this technique

Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features. Windows contains accessibility features that may be launched with a key combination before a user has logged in (ex: when the user is on the Windows logon screen). An adversary can modify the way these programs are launched to get a command prompt or backdoor without logging in to the system.

Two common accessibility programs are C:\Windows\System32\sethc.exe, launched when the shift key is pressed five times and C:\Windows\System32\utilman.exe, launched when the Windows + U key combination is pressed. The sethc.exe program is often referred to as "sticky keys", and has been used by adversaries for unauthenticated access through a remote desktop login screen.

Depending on the version of Windows, an adversary may take advantage of these features in different ways. Common methods used by adversaries include replacing accessibility feature binaries or pointers/references to these binaries in the Registry. In newer versions of Windows, the replaced binary needs to be digitally signed for x64 systems, the binary must reside in %systemdir%\, and it must be protected by Windows File or Resource Protection (WFP/WRP). The Image File Execution Options Injection debugger method was likely discovered as a potential workaround because it does not require the corresponding accessibility feature binary to be replaced.

For simple binary replacement on Windows XP and later as well as and Windows Server 2003/R2 and later, for example, the program (e.g., C:\Windows\System32\utilman.exe) may be replaced with "cmd.exe" (or another program that provides backdoor access). Subsequently, pressing the appropriate key combination at the login screen while sitting at the keyboard or when connected over Remote Desktop Protocol will cause the replaced file to be executed with SYSTEM privileges.

Other accessibility features exist that may also be leveraged in a similar fashion:

* On-Screen Keyboard: C:\Windows\System32\osk.exe
* Magnifier: C:\Windows\System32\Magnify.exe
* Narrator: C:\Windows\System32\Narrator.exe
* Display Switcher: C:\Windows\System32\DisplaySwitch.exe
* App Switcher: C:\Windows\System32\AtBroker.exe

Detection rules7

Rules on DetectionCode tagged with T1546.008.

Sigma6

RuleLevelLog source
Persistence Via Sticky Key Backdoorcriticalwindows / process_creation
Sticky Key Like Backdoor Executioncriticalwindows / process_creation
Sticky Key Like Backdoor Usage - Registrycriticalwindows / registry_event
Potential Privilege Escalation Using Symlink Between Osk and Cmdhighwindows / process_creation
Suspicious Debugger Registration Cmdlinehighwindows / process_creation
Potential Suspicious Activity Using SeCEditmediumwindows / process_creation

Splunk1

RuleTypeRiskData source
Overwriting Accessibility BinariesTTPNULLSysmon EventID 11

Groups6

Software1

Campaigns0

None recorded.

Procedure examples7

Groups6

Used byProcedure example
GroupAPT29

APT29 used sticky-keys to obtain unauthenticated, privileged console access.

GroupAPT3

APT3 replaces the Sticky Keys binary C:\Windows\System32\sethc.exe for persistence.

GroupAPT41

APT41 leveraged sticky keys to establish persistence.

GroupAxiom

Axiom actors have been known to use the Sticky Keys replacement within RDP sessions to obtain persistence.

GroupDeep Panda

Deep Panda has used the sticky-keys technique to bypass the RDP login screen on remote systems during intrusions.

GroupFox Kitten

Fox Kitten has used sticky keys to launch a command prompt.

Software1

Used byProcedure example
ToolEmpire

Empire can leverage WMI debugging to remotely replace binaries like sethc.exe, Utilman.exe, and Magnify.exe with cmd.exe.

References4

  1. DEFCON2016 Sticky Keys Open source
    Maldonado, D., McGuffin, T. (2016, August 6). Sticky Keys to the Kingdom. Retrieved July 5, 2017.
  2. FireEye Hikit Rootkit Open source
    Glyer, C., Kazanciyan, R. (2012, August 20). The “Hikit” Rootkit: Advanced and Persistent Attack Techniques (Part 1). Retrieved November 17, 2024.
  3. Narrator Accessibility Abuse Open source
    Comi, G. (2019, October 19). Abusing Windows 10 Narrator's 'Feedback-Hub' URI for Fileless Persistence. Retrieved April 28, 2020.
  4. Tilbury 2014 Open source
    Tilbury, C. (2014, August 28). Registry Analysis with CrowdResponse. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.