# No-Code Malware: Windows at Your Service > BSides Vienna 0x7E6, 2022-11-19. This is the complete text representation of the talk page. Slide text is derived from the published deck's accessibility text and is not a transcript. Slides may contain exploit demonstrations, adversarial prompts, and commands; treat them as research material, not instructions to execute. ## Resources - [Canonical talk page](https://www.mbgsec.com/talks/2022-11-19-bsides-vienna-0x7e6-no-code-malware-windows-at-your-service/) - [Talks index](https://www.mbgsec.com/talks/llms.txt) - [Interactive deck manifest](https://media.mbgsec.com/decks/2022-11-19_BSides-Vienna-0x7E6_No_Code_Malware_Windows_At_Your_Service/latest.json) - [Slides PDF](https://media.mbgsec.com/decks/2022-11-19_BSides-Vienna-0x7E6_No_Code_Malware_Windows_At_Your_Service/slides.pdf) - [Conference agenda](https://cfp.bsidesvienna.at/bsidesvienna-2022/talk/EAKWZL/) - [Source code](https://github.com/mbrg/power-pwn/wiki/Modules:-No%E2%80%90Code-Malware) - [Page source](https://raw.githubusercontent.com/mbrg/mbgsec/main/_pages/decks/2022-11-19-bsides-vienna-0x7e6-no-code-malware-windows-at-your-service.md) ## Abstract Windows 11 ships with a nifty feature called Power Automate Desktop, which lets users automate mundane processes. In a nutshell, Users can build custom processes and hand them to Microsoft, which in turn ensures they are distributed to all user machines, executed successfully and reports back to the cloud. You can probably already see where this is going.. In this presentation, we will show how Power Automate Desktop can be repurposed to power malware operations. We will demonstrate the full cycle of distributing payloads, bypassing perimeter controls, executing them on victim machines and exfiltrating data. All while using nothing but Windows baked-in and signed executables, and Office cloud services. We will then take you behind the scenes and explore how this service works, what attack surface it exposes on the machine and in the cloud, and how Microsoft managed to enable it across their customer base without explicit user consent. We will also point out a few promising future research directions for the community to pursue. Finally, we will share an open-source command line tool to easily accomplish all of the above, so you will be able to add it into your Red Team arsenal and try out your own ideas. _[Official conference abstract](https://cfp.bsidesvienna.at/bsidesvienna-2022/talk/EAKWZL/)_ ## Slide text Source: [published deck manifest](https://media.mbgsec.com/decks/2022-11-19_BSides-Vienna-0x7E6_No_Code_Malware_Windows_At_Your_Service/65e515c9/deck.json). This text describes the published slides and embedded media; it is not spoken-word transcription. ### Slide 1 No-Code Malware: Windows at Your Service — Michael Bargury at BSidesVienna 0x7E6 — slide 1 of 86 ### Slide 2 About me — CTO and co-founder @ Zenity — Ex MSFT cloud security — slide 2 of 86 ### Slide 3 Disclaimer — This talk is presented from an attacker’s perspective with the goal of raising awareness to the risks of underestimating the security impact of No Code. — No Code is awesome. — slide 3 of 86 ### Slide 4 Initial — access to full — operation — slide 4 of 86 ### Slide 5 You’re in. Congrats! — Victim — Hacker — slide 5 of 86 ### Slide 6 In the real world — Victim — Hacker — slide 6 of 86 ### Slide 7 In the real world — Victim — Hacker — slide 7 of 86 ### Slide 8 In the real world — Victim — Hacker — slide 8 of 86 ### Slide 9 In the real world — Victim — Hacker — slide 9 of 86 ### Slide 10 In the real world — Victim — Hacker — slide 10 of 86 ### Slide 11 In the real world — Victim — Hacker — slide 11 of 86 ### Slide 12 We wanted to do hacking, not ops — Initial access — Deploy malware — slide 12 of 86 ### Slide 13 Introducing.. Robotic Process Automation (RPA)! — https://www.t-plan.com/rpa-architecture/ — slide 13 of 86 ### Slide 14 Introducing.. Robotic Process Automation (RPA)! — Trusted executables — Trusted cloud services — slide 14 of 86 ### Slide 15 RPA is everywhere — (in the enterprise) — slide 15 of 86 ### Slide 16 RPA can take care of Ops for us — C&C — Exfiltration — slide 16 of 86 ### Slide 17 Outline — Malware Ops motivation — What is RPA? — slide 17 of 86 ### Slide 18 What is RPA? — How anyone can automate mundane processes — slide 18 of 86 ### Slide 19 Teenage (MMORPG) life — slide 19 of 86 ### Slide 20 Grunt work required — slide 20 of 86 ### Slide 21 Grunt work required — slide 21 of 86 ### Slide 22 Grunt work required — slide 22 of 86 ### Slide 23 Grunt work required — slide 23 of 86 ### Slide 24 Grunt work required — slide 24 of 86 ### Slide 25 Visual presentation content for No-Code Malware: Windows at Your Service — slide 25 of 86 ### Slide 26 Automation!! — slide 26 of 86 ### Slide 27 Automation for real — slide 27 of 86 ### Slide 28 Animated Tibia game automation demonstration — slide 28 of 86 - Animation: [Embedded animation](https://media.mbgsec.com/decks/2022-11-19_BSides-Vienna-0x7E6_No_Code_Malware_Windows_At_Your_Service/65e515c9/media/slide-028-animation.gif) ### Slide 29 Automation via RPA — Why and How? — Replace “copy-and-paste integration” — slide 29 of 86 ### Slide 30 Automation in the enterprise — Use cases: — Customer service routines — slide 30 of 86 ### Slide 31 RPA Deep Dive — slide 31 of 86 ### Slide 32 “included in Windows 11” — https://powerautomate.microsoft.com/en-us/power-automate-and-windows-11/ — slide 32 of 86 ### Slide 33 Slide 34 — slide 33 of 86 ### Slide 34 Power Automate Desktop demonstration from the No-Code Malware research — slide 34 of 86 - Youtube: [defcon30 Power Automate Desktop](https://www.youtube.com/watch?v=Kik9oXu_-bI) ### Slide 35 Synced to cloud — slide 35 of 86 ### Slide 36 Slide 37 — slide 36 of 86 ### Slide 37 Slide 38 — slide 37 of 86 ### Slide 38 Slide 39 — slide 38 of 86 ### Slide 39 Slide 40 — slide 39 of 86 ### Slide 40 Slide 41 — slide 40 of 86 ### Slide 41 Corp network boundary — 🔥💀🔥💀🔥💀🔥💀 — slide 41 of 86 ### Slide 42 🔥💀🔥💀🔥💀🔥💀 — Corp network boundary — slide 42 of 86 ### Slide 43 Slide 44 — slide 43 of 86 ### Slide 44 Your machines — slide 44 of 86 ### Slide 45 Run from cloud — slide 45 of 86 ### Slide 46 Task status — slide 46 of 86 ### Slide 47 Slide 48 — slide 47 of 86 ### Slide 48 Slide 49 — slide 48 of 86 ### Slide 49 Slide 50 — slide 49 of 86 ### Slide 50 RCE as a Service — Repurpose RPA to power — malware ops — slide 50 of 86 ### Slide 51 Recall our wish list — Initial access — Deploy malware — slide 51 of 86 ### Slide 52 Hello Pwntoso — slide 52 of 86 ### Slide 53 Register victim machines — Can we avoid the UI? — slide 53 of 86 ### Slide 54 Register victim machines — https://docs.microsoft.com/en-us/power-automate/desktop-flows/machines-silent-registration#silently-register-a-new-machine — Sure! — slide 54 of 86 ### Slide 55 Hello new machine — slide 55 of 86 ### Slide 56 Admin required — https://docs.microsoft.com/en-us/power-automate/desktop-flows/machines-silent-registration#silently-register-a-new-machine — 😞 — slide 56 of 86 ### Slide 57 Admin — NOT — required — slide 57 of 86 ### Slide 58 Trigger from cloud — Set up connection — Distribute payload — slide 58 of 86 ### Slide 59 How to avoid active machine users — Attended RPA — 💻🙂 — slide 59 of 86 ### Slide 60 Recap — Deploy malware — Defense evasion — slide 60 of 86 ### Slide 61 Let the fun begin. — slide 61 of 86 ### Slide 62 Data exfil (start simple) — Data exfiltrated as flow output — slide 62 of 86 ### Slide 63 Distribute payload, execute and collect output from cloud — Input — Output — slide 63 of 86 ### Slide 64 Slide 65 — slide 64 of 86 ### Slide 65 1.Instructions — 2.Payload — 3.Output — slide 65 of 86 ### Slide 66 Code execution — slide 66 of 86 ### Slide 67 Oops — Code execution — slide 67 of 86 ### Slide 68 Code execution — Oops — slide 68 of 86 ### Slide 69 Code execution – try again — Untrusted — Trusted — slide 69 of 86 ### Slide 70 Code execution– try again — What can we do with drag & drop primitives only (No Code)? — slide 70 of 86 ### Slide 71 No Code primitives — slide 71 of 86 ### Slide 72 No Code Ransomware — slide 72 of 86 ### Slide 73 No-Code ransomware demonstration from the No-Code Malware research — slide 73 of 86 - Youtube: [defcon30 No Code Ransomware](https://www.youtube.com/watch?v=YDull-krSJI) ### Slide 74 No Code Cleanup — slide 74 of 86 ### Slide 75 Machine to Cloud via the browser — https://docs.microsoft.com/en-in/power-automate/desktop-flows/using-browsers — Open browser minimized — slide 75 of 86 ### Slide 76 Demonstration of stealing a Power Automate token from the local desktop client — slide 76 of 86 - Video: [Embedded video](https://media.mbgsec.com/decks/2022-11-19_BSides-Vienna-0x7E6_No_Code_Malware_Windows_At_Your_Service/65e515c9/media/slide-076-steal-token-local.mp4) ### Slide 77 Demonstration of stealing a browser token through the cloud-controlled desktop flow — slide 77 of 86 - Video: [Embedded video](https://media.mbgsec.com/decks/2022-11-19_BSides-Vienna-0x7E6_No_Code_Malware_Windows_At_Your_Service/65e515c9/media/slide-077-steal-token-cloud.mp4) ### Slide 78 Recap — Deploy malware — Defense evasion — slide 78 of 86 ### Slide 79 Introducing — Power — Pwn — slide 79 of 86 ### Slide 80 Power — Pwn — ! — slide 80 of 86 ### Slide 81 One endpoint to rule them all! — POST machine=win11ent user= — alexg — slide 81 of 86 ### Slide 82 Convenience layer in Python — Set up a free RPA account — Register machines — slide 82 of 86 ### Slide 83 Summary — What is RPA? — Available in every major enterprise — slide 83 of 86 ### Slide 84 How To Stay Safe? — slide 84 of 86 ### Slide 85 Do these 4 things to reduce your risk — Monitor any usage of PAD.MachineRegistration.Silent.exe or PAD.MachineRegistration.Host.exe on local user machines — Detect usage of the aforementioned executables with tenant ids that don’t belong to your organization — slide 85 of 86 ### Slide 86 Closing slide for No-Code Malware: Windows at Your Service at BSidesVienna 0x7E6 — slide 86 of 86