BSidesLV 2023 · 2023/08
Wolves in Windows Clothing: Weaponizing Trusted Services for Stealthy Malware
Abstract
Windows 11 ships with a nifty feature called Power Automate, which lets users automate mundane processes. In a nutshell, Users can build custom processes and hand them to Microsoft, which in turn ensures they are distributed to all user machines, executed successfully and reports back to the cloud. You can probably already see where this is going..
In this talk, we will show how Power Automate can be repurposed to power malware operations. We will demonstrate the full cycle of distributing payloads, bypassing perimeter controls, executing them on victim machines and exfiltrating data. All while using nothing but Windows baked-in and signed executables, and Office cloud services.
We will go behind the scenes exploring how this service works, what attack surface it exposes on machine and cloud, and how Microsoft managed to enable it without explicit user consent. We will demonstrate how Office cloud services can be harnessed to act as a C2 server making detection and attribution extremely difficult.
Finally, we will share an open-source command line tool to easily accomplish all of the above, so you will be able to add it into your Red Team arsenal and try out your own ideas.
Transcript status
No transcript was published because two independent recording-derived transcription passes failed the machine publication gate. Two independent recording-derived ASR passes (mlx-community/whisper-large-v3-turbo, mlx-community/whisper-large-v3-mlx) failed the machine publication gate on 2026-08-14: deterministic checks: asr-artifact-quality. No transcript text was generated or manually filled.