# Malware Powered by Windows 11 No-Code > BSides Singapore 2022, 2022-09-22. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2022-09-22-bsides-singapore-2022-malware-powered-by-windows-11-no-code/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2022-09-22_Bsides-Singapore-2022_Malware_Powered_by_Windows_11_No_Code/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2022-09-22_Bsides-Singapore-2022_Malware_Powered_by_Windows_11_No_Code/slides.pdf) - [Conference agenda](https://bsidessg.org/archive/bsidessg2022/) - [Source code](https://github.com/mbrg/power-pwn/wiki/Modules:-No%E2%80%90Code-Malware) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2022-09-22-bsides-singapore-2022-malware-powered-by-windows-11-no-code.md) ## Abstract Windows 11 ships with a nifty feature called Power Automate, which lets users automate mundane processes. In a nutshell, Users can build custom processes and hand them to Microsoft, which in turn ensures they are distributed to all user machines or Office cloud, executed successfully and reports back to the cloud. You can probably already see where this is going.. In this presentation, we will show how Power Automate can be repurposed to power malware operations. We will demonstrate the full cycle of distributing payloads, bypassing perimeter controls, executing them on victim machines and exfiltrating data. All while using nothing but Windows baked-in and signed executables, and Office cloud services. We will then take you behind the scenes and explore how this service works, what attack surface it exposes on the machine and in the cloud, and how it is enabled by-default and can be used without explicit user consent. We will also point out a few promising future research directions for the community to pursue. Finally, we will share an open-source command line tool to easily accomplish all of the above, so you will be able to add it into your Red Team arsenal and try out your own ideas. _[Official agenda abstract for this talk, sourced from DEFCON30](https://forum.defcon.org/node/241932)_ ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2022-09-22_Bsides-Singapore-2022_Malware_Powered_by_Windows_11_No_Code/a47e5d49/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 MALWARE POWERED BY WIN11 NO-CODE Michael Bargury @mbrg0 github.com/mbrg/talks — slide 1 of 87 ### Slide 2 Abstract Windows 11 includes a handy feature called Power Automate Desktop, which lets users automate mundane tasks. In a nutshell, Users can build custom processes and hand them to Microsoft, which in turn ensures they are distributed to all user machines, executed successfully and reports back to the cloud. You can probably already see where this is going.. We will show how Power Automate Desktop can be repurposed to power malware operations. We will demonstrate the full cycle of distributing payloads, bypassing perimeter controls, executing them on victim machines and exfiltrating data. All while using nothing but Windows baked-in and signed executables, and Office cloud services. We will then take you behind the scenes and explore how this service works and what attack surface it exposes on the machine and in the cloud. We will also point out a few promising future research directions for the community to pursue. Finally, we will share an open-source command line tool to easily accomplish all of the above, so you will be able to add it into your Red Team arsenal and try out your own ideas. — slide 2 of 87 ### Slide 3 About me CTO and co-founder @ Zenity Ex MSFT cloud security OWASP ‘Top 10 LCNC Security Risks’ project lead Dark Reading columnist @mbrg0 bit.ly/ lcsec — slide 3 of 87 ### Slide 4 Disclaimer This talk is presented from an attacker’s perspective with the goal of raising awareness to the risks of underestimating the security impact of No Code. No Code is awesome. — slide 4 of 87 ### Slide 5 Initial access to full operation So you want to build a malware op — slide 5 of 87 ### Slide 6 You’re in. Congrats! Victim Hacker Initial access — slide 6 of 87 ### Slide 7 In the real world Victim Hacker EDR 🔥🔥🔥🔥🔥🔥🔥🔥 FW Corpnet Internet Initial access — slide 7 of 87 ### Slide 8 In the real world Victim Hacker EDR 🔥🔥🔥🔥🔥🔥🔥🔥 FW Corpnet Internet Initial access Run malware — slide 8 of 87 ### Slide 9 In the real world Victim Hacker EDR C&C 🔥🔥🔥🔥🔥🔥🔥🔥 FW Internet Corpnet Initial access Run malware — slide 9 of 87 ### Slide 10 In the real world Victim Hacker EDR C&C Exfiltration 🔥🔥🔥🔥🔥🔥🔥🔥 FW Internet Corpnet Initial access Run malware — slide 10 of 87 ### Slide 11 In the real world Victim Hacker EDR Defense evasion C&C Exfiltration 🔥🔥🔥🔥🔥🔥🔥🔥 FW Internet Corpnet Initial access Run malware — slide 11 of 87 ### Slide 12 In the real world Victim Hacker Initial access Persistency EDR Defense evasion C&C Exfiltration 🔥🔥🔥🔥🔥🔥🔥🔥 FW Internet Corpnet Run malware — slide 12 of 87 ### Slide 13 We wanted to do hacking, not ops Initial access Deploy malware C&C Exfiltration Defense evasion Persistency Cleanup … .. Profit Malware Ops — slide 13 of 87 ### Slide 14 Introducing.. Robotic Process Automation (RPA)! https://www.t-plan.com/rpa-architecture/ — slide 14 of 87 ### Slide 15 Introducing.. Robotic Process Automation (RPA)! Trusted executables Trusted cloud services Trusted communication https://www.t-plan.com/rpa-architecture/ — slide 15 of 87 ### Slide 16 RPA is everywhere (in the enterprise) — slide 16 of 87 ### Slide 17 RPA can take care of Ops for us C&C Exfiltration Defense evasion Persistency Cleanup And so much more: Handle errors Support different OS/versions Malware updates Aggregate data across machines … — slide 17 of 87 ### Slide 18 Outline Malware Ops motivation What is RPA? RPA technical deep dive Abusing RPA: RCE as a Service Introducing Power Pwn Defense: 4 things to do when you get home — slide 18 of 87 ### Slide 19 What is RPA? How anyone can automate mundane processes — slide 19 of 87 ### Slide 20 Teenage (MMORPG) life — slide 20 of 87 ### Slide 21 Grunt work required — slide 21 of 87 ### Slide 22 Grunt work required — slide 22 of 87 ### Slide 23 Grunt work required — slide 23 of 87 ### Slide 24 Grunt work required — slide 24 of 87 ### Slide 25 Grunt work required — slide 25 of 87 ### Slide 26 Profit! — slide 26 of 87 ### Slide 27 Automation!! — slide 27 of 87 ### Slide 28 Automation for real — slide 28 of 87 ### Slide 29 https://youtube.com/clip/UgkxqPRYueIjN24IqUs5iw13meeh7mm3KdNr Automation for real — slide 29 of 87 - Animation: [Embedded animation](https://media.mbgsec.com/decks/2022-09-22_Bsides-Singapore-2022_Malware_Powered_by_Windows_11_No_Code/a47e5d49/media/automation-for-real.gif) ### Slide 30 Automation via RPA Why and How? Replace “copy-and-paste integration” Drag & drag builder Emulate user actions (mouse/keyboard) to connect Runs on user machines / dedicated servers — slide 30 of 87 ### Slide 31 Automation in the enterprise Use cases: Customer service routines Finance payments and reporting HR onboarding / offboarding Supply chain keep inventory up to date Procurement invoice processing Why and How? Replace “copy-and-paste integration” Drag & drag builder Emulate user actions (mouse/keyboard) to connect Runs on user machines / dedicated servers — slide 31 of 87 ### Slide 32 RPA Deep Dive — slide 32 of 87 ### Slide 33 “included in Windows 11” https://powerautomate.microsoft.com/en-us/power-automate-and-windows-11/ — slide 33 of 87 ### Slide 34 Windows 11 desktop showing Power Automate search results beside Microsoft documentation that Power Automate is preinstalled in Windows 11 — slide 34 of 87 ### Slide 35 youtu.be/Kik9oXu_-bI — slide 35 of 87 - Youtube: [defcon30 Power Automate Desktop](https://www.youtube.com/watch?v=Kik9oXu_-bI) ### Slide 36 Synced to cloud — slide 36 of 87 ### Slide 37 Architecture diagram with Power Automate on Windows 11 and Office cloud services separated by the on-premises and Microsoft cloud boundary — slide 37 of 87 ### Slide 38 Architecture diagram showing the UIFlowService user connecting Power Automate to the machine runtime on Windows 11 — slide 38 of 87 ### Slide 39 Architecture diagram with Power Automate browser-extension setup screenshots for Microsoft Edge — slide 39 of 87 ### Slide 40 Architecture diagram showing Power Automate connected to Chrome, Firefox, and Edge through the machine runtime — slide 40 of 87 ### Slide 41 Architecture diagram with Windows Explorer highlighting Power Automate Desktop application executables — slide 41 of 87 ### Slide 42 Corp network boundary 🔥💀🔥💀🔥💀🔥💀 — slide 42 of 87 ### Slide 43 🔥💀🔥💀🔥💀🔥💀 Corp network boundary — slide 43 of 87 ### Slide 44 Architecture diagram showing the machine runtime making an outbound connection through the corporate network boundary to Azure Service Bus and Office cloud services — slide 44 of 87 ### Slide 45 Your machines — slide 45 of 87 ### Slide 46 Run from cloud — slide 46 of 87 ### Slide 47 Task status — slide 47 of 87 ### Slide 48 Architecture diagram showing Power Automate and browsers connecting through the machine runtime and Azure Service Bus to Office cloud services — slide 48 of 87 ### Slide 49 Architecture diagram adding the machine private key and Office cloud public key to the Power Automate connection — slide 49 of 87 ### Slide 50 Architecture diagram adding local credentials and an RPA task to the Azure Service Bus connection — slide 50 of 87 ### Slide 51 RCE as a Service Repurpose RPA to power malware ops — slide 51 of 87 ### Slide 52 Recall our wish list Initial access Deploy malware Defense evasion Persistency C&C Exfiltration Cleanup … .. Profit Malware Ops — slide 52 of 87 ### Slide 53 Hello Pwntoso — slide 53 of 87 ### Slide 54 Register victim machines Can we avoid the UI? — slide 54 of 87 ### Slide 55 Register victim machines https://docs.microsoft.com/en-us/power-automate/desktop-flows/machines-silent-registration#silently-register-a-new-machine Sure! Can we avoid the UI? — slide 55 of 87 ### Slide 56 Hello new machine — slide 56 of 87 ### Slide 57 Admin required https://docs.microsoft.com/en-us/power-automate/desktop-flows/machines-silent-registration#silently-register-a-new-machine 😞 — slide 57 of 87 ### Slide 58 Admin NOT required 🤓 — slide 58 of 87 ### Slide 59 Trigger from cloud Set up connection Distribute payload Cloud setup — slide 59 of 87 ### Slide 60 How to avoid active machine users Attended RPA 💻🙂 Unattended RPA 🤖 Create a new local user session Leverage an existing local user session — slide 60 of 87 ### Slide 61 Recap Deploy malware Defense evasion Persistency C&C Exfiltration Cleanup — slide 61 of 87 ### Slide 62 Let the fun begin. — slide 62 of 87 ### Slide 63 Data exfil (start simple) Data exfiltrated as flow output — slide 63 of 87 ### Slide 64 Distribute payload, execute and collect output from cloud Input Output — slide 64 of 87 ### Slide 65 Architecture diagram of Power Automate and browsers on Windows 11 connecting through the machine runtime and Azure Service Bus to Office cloud services — slide 65 of 87 ### Slide 66 1.Instructions 2.Payload 3.Output — slide 66 of 87 ### Slide 67 Code execution — slide 67 of 87 ### Slide 68 Oops Code execution — slide 68 of 87 ### Slide 69 Code execution Oops — slide 69 of 87 ### Slide 70 Code execution – try again Untrusted Trusted — slide 70 of 87 ### Slide 71 Code execution– try again What can we do with drag & drop primitives only (No Code)? — slide 71 of 87 ### Slide 72 No Code primitives — slide 72 of 87 ### Slide 73 No Code Ransomware — slide 73 of 87 ### Slide 74 youtu.be/ YDull-krSJI — slide 74 of 87 - Youtube: [defcon30 No Code Ransomware](https://www.youtube.com/watch?v=YDull-krSJI) ### Slide 75 No Code Cleanup — slide 75 of 87 ### Slide 76 Machine to Cloud via the browser https://docs.microsoft.com/en-in/power-automate/desktop-flows/using-browsers Open browser minimized Go to flow.microsoft.com Hit CTRL+U Extract access token from header — slide 76 of 87 ### Slide 77 youtu.be/lY_RzV-4BdI — slide 77 of 87 - Video: [Embedded video](https://media.mbgsec.com/decks/2022-09-22_Bsides-Singapore-2022_Malware_Powered_by_Windows_11_No_Code/a47e5d49/media/steal-browser-token-local.mp4) ### Slide 78 youtu.be/zlF7np18oGI — slide 78 of 87 - Video: [Embedded video](https://media.mbgsec.com/decks/2022-09-22_Bsides-Singapore-2022_Malware_Powered_by_Windows_11_No_Code/a47e5d49/media/steal-browser-token-cloud.mp4) ### Slide 79 Recap Deploy malware Defense evasion Persistency C&C Exfiltration Cleanup And more: Creds access via browser — slide 79 of 87 ### Slide 80 Introducing Power Pwn ! — slide 80 of 87 ### Slide 81 Power Pwn ! Trigger via HTTP Seamlessly handle errors and edge cases — slide 81 of 87 ### Slide 82 One endpoint to rule them all! POST machine=win11ent user= alexg payload=ransomware dir =C:\ encryptionKey =9d0d578115a2734a SUCCESS filesFound =71892 filesProcessed =70497 — slide 82 of 87 ### Slide 83 Convenience layer in Python Set up a free RPA account Register machines Profit github.com/mbrg/power-pwn — slide 83 of 87 ### Slide 84 Summary What is RPA? Available in every major enterprise Technical deep dive Abusing RPA: RCE as a Service Distribute and execute payloads thru trusted services No Code primitives Introducing Power Pwn Defense: 4 things to do when you get home — slide 84 of 87 ### Slide 85 How To Stay Safe? — slide 85 of 87 ### Slide 86 Do these 4 things to reduce your risk Monitor any usage of PAD.MachineRegistration.Silent.exe or PAD.MachineRegistration.Host.exe on local user machines Detect usage of the aforementioned executables with tenant ids that don’t belong to your organization Review you own tenant’s Power Automate environment and Microsoft best practice . If you’re a Microsoft shop, your users are probably already using it! Learn more at OWASP , Dark Reading , Zenity blog — slide 86 of 87 ### Slide 87 MALWARE POWERED BY WIN11 NO-CODE Michael Bargury @mbrg0 github.com/mbrg/talks — slide 87 of 87