PULSE NAME
Accessibility Features - CAPE Sandbox
WHITE msudosos 2026-05-31 Modified: 2026-05-31
214
IOCs
HIGH VOLUME
Malicious actors are increasingly weaponizing accessibility features—such as virtual screen readers, braille terminal emulators, and digital mobility assistance interfaces—as high-utility attack vectors. While these frameworks are legally mandated for vulnerable user populations, they inherently require deep operating system permissions, making them primary targets for exploitation. Malicious API Hooking & Keylogging: Attackers leverage UI Automation and Screen Reader APIs to bypass standard process isolation. By mimicking a legitimate vision-assistance tool, malware can intercept keystrokes, harvest active session credentials, and read sensitive on-screen data (vision prescription/medical records) directly from the application layer. Braille or virtual keyboard input pipeline, transparently altering the user's typed characters to change the semantic meaning of outbound communications or commands. research -tbc.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (6 / 214 total)
All FileHash-MD5 FileHash-SHA1 IPv4 URL domain hostname FileHash-SHA256 email Mutex
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 5345904ead8e4e1d5bb5983d0f57e216 2026-05-31
FileHash-MD5 8441280b0c35cbc1147f8ba998a563a7 2026-05-31
FileHash-MD5 6b7412fb82ca5edfd0917e3957f05d89 2026-05-31
FileHash-MD5 1afb6064d17d0025ad05ac12c0740d97 2026-05-31
FileHash-MD5 64efec9f0dd2955de50c14dacfe76f41 2026-05-31
FileHash-MD5 29cbbe1e83654940b8aef050d6c46c9a 2026-05-31