Work Folders
Execute control.exe in the current working directory
WorkFolders
Can be used to evade defensive countermeasures or to hide as a persistence mechanism
WorkFolders attempts to execute control.exe. By modifying the default value of the App Paths registry key for control.exe in HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\control.exe, an attacker can achieve proxy execution.
WorkFolders
Proxy execution of a malicious payload via App Paths registry hijacking.