# Wolves in Windows Clothing: Weaponizing Trusted Services for Stealthy Malware > BSidesLV 2023, 2023-08-09. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2023-08-09-bsideslv-2023-wolves-in-windows-clothing-weaponizing-trusted-services-for-stealthy-malware/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2023-08-09_BSidesLV-2023_Wolves_in_Windows_Clothing/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2023-08-09_BSidesLV-2023_Wolves_in_Windows_Clothing/slides.pdf) - [Recording](https://www.youtube.com/watch?v=4L5lPqgAgR4&t=7426s) - [Conference agenda](https://archive.bsideslv.org/2023/talks#wolves-in-windows-clothing-weaponizing-trusted-services-for-stealthy-malware) - [Source code](https://github.com/mbrg/power-pwn) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2023-08-09-bsideslv-2023-wolves-in-windows-clothing-weaponizing-trusted-services-for-stealthy-malware.md) ## Abstract Windows 11 ships with a nifty feature called Power Automate, which lets users automate mundane processes. In a nutshell, Users can build custom processes and hand them to Microsoft, which in turn ensures they are distributed to all user machines, executed successfully and reports back to the cloud. You can probably already see where this is going.. In this talk, we will show how Power Automate can be repurposed to power malware operations. We will demonstrate the full cycle of distributing payloads, bypassing perimeter controls, executing them on victim machines and exfiltrating data. All while using nothing but Windows baked-in and signed executables, and Office cloud services. We will go behind the scenes exploring how this service works, what attack surface it exposes on machine and cloud, and how Microsoft managed to enable it without explicit user consent. We will demonstrate how Office cloud services can be harnessed to act as a C2 server making detection and attribution extremely difficult. Finally, we will share an open-source command line tool to easily accomplish all of the above, so you will be able to add it into your Red Team arsenal and try out your own ideas. _[Official conference abstract](https://archive.bsideslv.org/2023/talks#wolves-in-windows-clothing-weaponizing-trusted-services-for-stealthy-malware)_ ## Transcript status No transcript was published because two independent recording-derived transcription passes failed the machine publication gate. Two independent recording-derived ASR passes (mlx-community/whisper-large-v3-turbo, mlx-community/whisper-large-v3-mlx) failed the machine publication gate on 2026-08-14: deterministic checks: asr-artifact-quality. No transcript text was generated or manually filled. ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2023-08-09_BSidesLV-2023_Wolves_in_Windows_Clothing/ba9ca767/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 Slide 1: Wolves in Windows Clothing: Weaponizing Trusted Services for Stealthy Malware Michael Bargury @ Zenity BSideLV 2023 Learn more: github.com/mbrg/talks Twitter: @mbrg0 ### Slide 2 Slide 2: CTO and Co-founder @ Zenity OWASP LCNC Top 10 project lead Dark Reading columnist Defcon, BSides, RSAC, OWASP Hiring top researchers, engs & pms! Hi there πŸ‘‹ @mbrg0 darkreading.com/author/ michael-bargury github.com/mbrg ### Slide 3 Slide 3: Initial access to full operation So you want to build a malware op @ mbrg0 ### Slide 4 Slide 4: You’re in. Congrats! Victim Hacker Initial access @ mbrg0 ### Slide 5 Slide 5: In the real world Victim Hacker EDR πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯ FW Corpnet Internet Initial access @ mbrg0 ### Slide 6 Slide 6: In the real world Victim Hacker EDR πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯ FW Corpnet Internet Initial access Run malware @ mbrg0 ### Slide 7 Slide 7: In the real world Victim Hacker EDR C&C πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯ FW Internet Corpnet Initial access Run malware @ mbrg0 ### Slide 8 Slide 8: In the real world Victim Hacker EDR C&C Exfiltration πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯ FW Internet Corpnet Initial access Run malware @ mbrg0 ### Slide 9 Slide 9: In the real world Victim Hacker EDR Defense evasion C&C Exfiltration πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯ FW Internet Corpnet Initial access Run malware @ mbrg0 ### Slide 10 Slide 10: In the real world Victim Hacker Initial access Persistency EDR Defense evasion C&C Exfiltration πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯πŸ”₯ FW Internet Corpnet Run malware @ mbrg0 ### Slide 11 Slide 11: We wanted to do hacking, not ops Initial access Deploy malware C&C Exfiltration Defense evasion Persistency Cleanup … .. Profit Malware Ops @ mbrg0 ### Slide 12 Slide 12: Introducing.. Robotic Process Automation (RPA)! https://www.t-plan.com/rpa-architecture/ @ mbrg0 ### Slide 13 Slide 13: Introducing.. Robotic Process Automation (RPA)! Trusted executables Trusted cloud services Trusted communication https://www.t-plan.com/rpa-architecture/ @ mbrg0 ### Slide 14 Slide 14: RPA is everywhere (in the enterprise) @ mbrg0 ### Slide 15 Slide 15: RPA can take care of Ops for us C&C Exfiltration Defense evasion Persistency Cleanup And so much more: Handle errors Support different OS/versions Malware updates Aggregate data across machines … @ mbrg0 ### Slide 16 Slide 16: Automation via RPA Why and How? Replace β€œcopy-and-paste integration” Drag & drag builder Emulate user actions (mouse/keyboard) to connect Runs on user machines / dedicated servers @ mbrg0 ### Slide 17 Slide 17: Automation in the enterprise Use cases: Customer service routines Finance payments and reporting HR onboarding / offboarding Supply chain keep inventory up to date Procurement invoice processing Why and How? Replace β€œcopy-and-paste integration” Drag & drag builder Emulate user actions (mouse/keyboard) to connect Run… ### Slide 18 Slide 18: Outline Malware Ops motivation What is RPA? RPA technical deep dive Abusing RPA: RCE as a Service Introducing Power Pwn Defense: 4 things to do when you get home @ mbrg0 ### Slide 19 Slide 19: What is RPA? How anyone can automate mundane processes @ mbrg0 ### Slide 20 Slide 20: Teenage (MMORPG) life @ mbrg0 ### Slide 21 Slide 21: Grunt work required @ mbrg0 ### Slide 22 Slide 22: Grunt work required @ mbrg0 ### Slide 23 Slide 23: Grunt work required @ mbrg0 ### Slide 24 Slide 24: Grunt work required @ mbrg0 ### Slide 25 Slide 25: Grunt work required @ mbrg0 ### Slide 26 Slide 26: Profit! @ mbrg0 ### Slide 27 Slide 27: Automation!! @ mbrg0 ### Slide 28 Slide 28: Automation for real @ mbrg0 ### Slide 29 Slide 29: https://youtube.com/clip/UgkxqPRYueIjN24IqUs5iw13meeh7mm3KdNr Automation for real @ mbrg0 - Animation: [Embedded animation](https://media.mbgsec.com/decks/2023-08-09_BSidesLV-2023_Wolves_in_Windows_Clothing/ba9ca767/media/automation-demo.gif) ### Slide 30 Slide 30: RPA Deep Dive @ mbrg0 ### Slide 31 Slide 31: β€œincluded in Windows 11” https://powerautomate.microsoft.com/en-us/power-automate-and-windows-11/ ### Slide 32 Slide 32: @ mbrg0 ### Slide 33 Slide 33: youtu.be/Kik9oXu_-bI @ mbrg0 - Youtube: [Power Automate Desktop demonstration](https://www.youtube.com/watch?v=Kik9oXu_-bI) ### Slide 34 Slide 34: Synced to cloud @ mbrg0 ### Slide 35 Slide 35: @ mbrg0 ### Slide 36 Slide 36: @ mbrg0 ### Slide 37 Slide 37: @ mbrg0 ### Slide 38 Slide 38: @ mbrg0 ### Slide 39 Slide 39: @ mbrg0 ### Slide 40 Slide 40: Corp network boundary πŸ”₯πŸ’€πŸ”₯πŸ’€πŸ”₯πŸ’€πŸ”₯πŸ’€ @ mbrg0 ### Slide 41 Slide 41: πŸ”₯πŸ’€πŸ”₯πŸ’€πŸ”₯πŸ’€πŸ”₯πŸ’€ Corp network boundary @ mbrg0 ### Slide 42 Slide 42: @ mbrg0 ### Slide 43 Slide 43: Your machines @ mbrg0 ### Slide 44 Slide 44: Run from cloud @ mbrg0 ### Slide 45 Slide 45: Task status @ mbrg0 ### Slide 46 Slide 46: RCE as a Service Repurpose RPA to power malware ops @ mbrg0 ### Slide 47 Slide 47: Recall our wish list Initial access Deploy malware Defense evasion Persistency C&C Exfiltration Cleanup … .. Profit Malware Ops @ mbrg0 ### Slide 48 Slide 48: Hello Pwntoso @ mbrg0 ### Slide 49 Slide 49: Register victim machines Can we avoid the UI? @ mbrg0 ### Slide 50 Slide 50: Register victim machines https://docs.microsoft.com/en-us/power-automate/desktop-flows/machines-silent-registration#silently-register-a-new-machine Sure! Can we avoid the UI? @ mbrg0 ### Slide 51 Slide 51: Hello new machine @ mbrg0 ### Slide 52 Slide 52: Admin required https://docs.microsoft.com/en-us/power-automate/desktop-flows/machines-silent-registration#silently-register-a-new-machine 😞 @ mbrg0 ### Slide 53 Slide 53: Admin NOT required πŸ€“ @ mbrg0 ### Slide 54 Slide 54: Trigger from cloud Set up connection Distribute payload Cloud setup @ mbrg0 ### Slide 55 Slide 55: How to avoid active machine users Attended RPA πŸ’»πŸ™‚ Unattended RPA πŸ€– Create a new local user session Leverage an existing local user session @ mbrg0 ### Slide 56 Slide 56: Recap Deploy malware Defense evasion Persistency C&C Exfiltration Cleanup @ mbrg0 ### Slide 57 Slide 57: Let the fun begin. @ mbrg0 ### Slide 58 Slide 58: Data exfil (start simple) Data exfiltrated as flow output @ mbrg0 ### Slide 59 Slide 59: Distribute payload, execute and collect output from cloud Input Output @ mbrg0 ### Slide 60 Slide 60: @ mbrg0 ### Slide 61 Slide 61: 1.Instructions 2.Payload 3.Output @ mbrg0 ### Slide 62 Slide 62: Code execution @ mbrg0 ### Slide 63 Slide 63: Oops Code execution @ mbrg0 ### Slide 64 Slide 64: Code execution Oops @ mbrg0 ### Slide 65 Slide 65: Code execution – try again Untrusted Trusted @ mbrg0 ### Slide 66 Slide 66: Code execution– try again What can we do with drag & drop primitives only (No Code)? @ mbrg0 ### Slide 67 Slide 67: No Code primitives @ mbrg0 ### Slide 68 Slide 68: No Code Ransomware @ mbrg0 ### Slide 69 Slide 69: youtu.be/ YDull-krSJI @ mbrg0 - Youtube: [No Code Ransomware demonstration](https://www.youtube.com/watch?v=YDull-krSJI) ### Slide 70 Slide 70: No Code Cleanup ### Slide 71 Slide 71: Machine to Cloud via the browser https://docs.microsoft.com/en-in/power-automate/desktop-flows/using-browsers Open browser minimized Go to flow.microsoft.com Hit CTRL+U Extract access token from header @ mbrg0 ### Slide 72 Slide 72: youtu.be/lY_RzV-4BdI @ mbrg0 - Video: [Machine-to-browser local token demonstration](https://media.mbgsec.com/decks/2023-08-09_BSidesLV-2023_Wolves_in_Windows_Clothing/ba9ca767/media/steal-browser-token-local.mp4) ### Slide 73 Slide 73: youtu.be/zlF7np18oGI @ mbrg0 - Video: [Machine-to-browser cloud token demonstration](https://media.mbgsec.com/decks/2023-08-09_BSidesLV-2023_Wolves_in_Windows_Clothing/ba9ca767/media/steal-browser-token-cloud.mp4) ### Slide 74 Slide 74: Recap Deploy malware Defense evasion Persistency C&C Exfiltration Cleanup And more: Creds access via browser @ mbrg0 ### Slide 75 Slide 75: Introducing Power Pwn (v2)! github.com/mbrg/power-pwn @ mbrg0 ### Slide 76 Slide 76: Power Pwn ! Trigger via HTTP Seamlessly handle errors and edge cases github.com/mbrg/power- pwn @ mbrg0 ### Slide 77 Slide 77: One endpoint to rule them all! POST machine=win11ent user= alexg payload=ransomware dir =C:\ encryptionKey =9d0d578115a2734a SUCCESS filesFound =71892 filesProcessed =70497 github.com/mbrg/power- pwn @ mbrg0 ### Slide 78 Slide 78: Find us at BlackHat Arsenal! PowerGuest: AAD Guest Exploitation Beyond Enumeration + on GitHub! github.com/mbrg/power- pwn @ mbrg0 ### Slide 79 Slide 79: Summary What is RPA? Available in every major enterprise Technical deep dive Abusing RPA: RCE as a Service Distribute and execute payloads thru trusted services No Code primitives Introducing Power Pwn Defense: 4 things to do when you get home @ mbrg0 ### Slide 80 Slide 80: How To Stay Safe? @ mbrg0 ### Slide 81 Slide 81: State of the exploit @ mbrg0 ### Slide 82 Slide 82: Sept 9, 2022 – Microsoft claims this is not an issue. State of the exploit https://www.wired.com/story/windows-11-power-automate-attack/ @ mbrg0 ### Slide 83 Slide 83: Sept 9, 2022 – Microsoft claims this is not an issue. May 4, 2023 – Microsoft issues a fix w/ no acknowledgement or CVE. State of the exploit https://support.microsoft.com/en-us/topic/tenant-restrictions-for-power-automate-desktop-machine-registration-f0b44662-7a18-403d-989a-c1445c376768 @ mbrg0 ### Slide 84 Slide 84: Sept 9, 2022 – Microsoft claims this is not an issue. May 4, 2023 – Microsoft issues a fix w/ no acknowledgement or CVE. Aug 2023 – Microsoft issues acknowledgement State of the exploit @ mbrg0 ### Slide 85 Slide 85: Sept 9, 2022 – Microsoft claims this is not an issue. May 4, 2023 – Microsoft issues a fix w/ no acknowledgement or CVE. Aug 2023 – Microsoft issues acknowledgement but refuses to issue a CVE. State of the exploit β€œthis case was investigated and determined to be defense in depth and social engineering requiring admi… ### Slide 86 Slide 86: Cases where this still works today Any machine that is not AAD-joined (i.e. consumers) Insecure configuration. Insecure flags include AllowRegisteringOutsideOfAADJoinedTenant and AllowTenantSwitching PAD v<2.24 is still vulnerable (no CVE or force update) @ mbrg0 ### Slide 87 Slide 87: Do these 4 things to reduce your risk Monitor any usage of PAD.MachineRegistration.Silent.exe or PAD.MachineRegistration.Host.exe on local user machines Detect usage of the aforementioned executables with tenant ids that don’t belong to your organization Review you own tenant’s Power Automate environment and Microso… ### Slide 88 Slide 88: Wolves in Windows Clothing: Weaponizing Trusted Services for Stealthy Malware Michael Bargury @ Zenity BSideLV 2023 Learn more: github.com/mbrg/talks Twitter: @mbrg0