{"id":5134,"date":"2025-07-05T10:04:09","date_gmt":"2025-07-05T10:04:09","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/05\/researchers-uncover-new-technique-to-exploit-azure-arc-for-hybrid-escalation-in-enterprise-environment-and-maintain-persistence\/"},"modified":"2025-07-05T10:04:09","modified_gmt":"2025-07-05T10:04:09","slug":"researchers-uncover-new-technique-to-exploit-azure-arc-for-hybrid-escalation-in-enterprise-environment-and-maintain-persistence","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/05\/researchers-uncover-new-technique-to-exploit-azure-arc-for-hybrid-escalation-in-enterprise-environment-and-maintain-persistence\/","title":{"rendered":"Researchers Uncover New Technique to Exploit Azure Arc for Hybrid Escalation in Enterprise Environment and Maintain Persistence"},"content":{"rendered":"<p>    Researchers Uncover New Technique to Exploit Azure Arc for Hybrid Escalation in Enterprise Environment and Maintain Persistence<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybersecurity researchers have discovered a sophisticated attack technique that exploits Microsoft Azure Arc deployments to gain persistent access to enterprise environments.<\/p>\n<p>The research, conducted during recent red team operations, reveals how adversaries can leverage misconfigured <a href=\"https:\/\/cybersecuritynews.com\/microsoft-boosts-msa-signing-service-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Azure Arc<\/a> installations to escalate privileges from cloud environments to on-premises systems and maintain long-term persistence through legitimate Microsoft services.<\/p>\n<p>Azure Arc, Microsoft\u2019s hybrid cloud management platform, extends Azure\u2019s native management capabilities to on-premises systems, Kubernetes clusters, and other non-Azure resources.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEitFSr3VzPEQ9uMSBA5TdSm1V7e6KkK6WmCHICmM6f_9NXx_xmeHW2GTcIaJU8SZQd50KXxDIFtFrcYa4Xk9lTUE2CQkEwnrTF01fYyWOQBCvvkkKRSE5ZpZWI9hVALN5LjRsgNXib6L5_SENSIVxZTaBJcmloQlKEbNYxtm0insgvwp8CLmnhg4KxfH60\/s16000\/Arc%2520management%2520overview%2520window%2520%28Source%2520-%2520IBM%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Arc management overview window (Source \u2013 IBM)<\/figcaption><\/figure>\n<\/div>\n<p>While designed to streamline hybrid infrastructure management, the service\u2019s deployment mechanisms and configuration processes have introduced new attack vectors that threat actors can exploit.<\/p>\n<p>The research demonstrates how attackers can identify Arc deployments in enterprise environments and abuse common misconfigurations to achieve code execution with system-level privileges.<\/p>\n<p>The attack techniques center around the exploitation of Service Principal credentials that are often hardcoded in deployment scripts or stored in <a href=\"https:\/\/cybersecuritynews.com\/from-phishing-to-ransomware-understanding-the-threats-in-your-network\/\" target=\"_blank\" rel=\"noreferrer noopener\">accessible network<\/a> shares.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgLVesm5qgCsSQXuthPUHCahsjEudgHBByb6O45PIx2g19E5ZNI_hGvWvuksvUVFY5Ut3me_dmV-FFcWA0wXskTu5uiGyaiZteiK7io_CVL9DhIXbqRkERnsmZGFOPIJWV9BS3gmede0MdxTzm5PjbQsmwfW0-itTbnUUm_u00853u4ObMEHNgYS6CIlSA\/s16000\/Assigning%2520roles%2520as%2520a%2520part%2520of%2520Service%2520Principal%2520creation%2520%28Source%2520-%2520IBM%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Assigning roles as a part of Service Principal creation (Source \u2013 IBM)<\/figcaption><\/figure>\n<\/div>\n<p>These credentials, originally intended for automated Arc client registration, can be recovered by attackers who gain access to deployment infrastructure or policy configurations.<\/p>\n<p>Once obtained, these credentials can be weaponized to execute arbitrary code on Arc-managed systems through various Azure management interfaces.<\/p>\n<p>IBM analysts <a href=\"https:\/\/www.ibm.com\/think\/x-force\/identifying-abusing-azure-arc-for-hybrid-escalation-persistence\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> multiple deployment vectors that introduce security vulnerabilities, including PowerShell scripts with embedded secrets, misconfigured System Center Configuration Manager (SCCM) deployments, and Group Policy Objects (GPOs) that store encrypted credentials using DPAPI-NG.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgFA0rzRd-PBXRGEXpeBDp5g5SSkXwV_z2Qq2NhyvrSrsWat993HKPPNG3zragBsguKLZ6AihmFCmdzYCC0BhunJdpbFE7GYJxvgG7stSP6Mshta2cAAUVzAZIzAn8Vqgq5bALU8cQaORodIudzSv6awu4PjefmC_tOOOcTZi1fyGkKsxvrzFrfKEEOCDE\/s16000\/Recovering%2520SCCM%2520script%2520used%2520to%2520deploy%2520Arc%2520from%2520SCCM%2520site%2520database%2520with%2520SQLRecon%2520%28Source%2520-%2520IBM%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Recovering SCCM script used to deploy Arc from SCCM site database with SQLRecon (Source \u2013 IBM)<\/figcaption><\/figure>\n<\/div>\n<p>The research team noted that these deployment methods, while following Microsoft\u2019s official guidance, often result in credential exposure due to overly permissive access controls and inadequate secret management practices.<\/p>\n<h2 class=\"wp-block-heading\"><strong>DPAPI-NG Exploitation and Credential Recovery<\/strong><\/h2>\n<p>The most significant finding involves the exploitation of DPAPI-NG encrypted secrets stored in Azure Arc deployment shares.<\/p>\n<p>When Arc is deployed via Group Policy, administrators create network shares containing deployment files, including an \u201cencryptedServicePrincipalSecret\u201d file protected by DPAPI-NG encryption.<\/p>\n<p>However, this encryption is configured to allow any member of the domain computers group to decrypt the secret, effectively making it accessible to any compromised system in the domain.<\/p>\n<p>The decryption process involves accessing the deployment share and using <a href=\"https:\/\/cybersecuritynews.com\/hackers-actively-exploiting-powershell\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> commands to retrieve the encrypted blob.<\/p>\n<p>Attackers can execute the following technique from any system with NT_AUTHORITYSYSTEM privileges:-<\/p>\n<pre class=\"wp-block-code\"><code>$encryptedSecret = Get-Content (Join-Path $SourceFilesFullPath \"encryptedServicePrincipalSecret\")\n# DPAPI-NG blob configured to allow any member of domain computers group to decrypt<\/code><\/pre>\n<p>This credential recovery method provides attackers with Service Principal access that can be immediately weaponized for code execution on Arc-managed systems.<\/p>\n<p>The research demonstrates that these recovered credentials often possess elevated privileges beyond their intended scope, including the \u201cAzure Connected Machine Resource Administrator\u201d role, which grants comprehensive management capabilities over Arc deployments.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=braodo_stealer&amp;utm_content=demo_1&amp;utm_term=250625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/researchers-uncover-new-technique-to-exploit-uncover-azure-arc\/\">Researchers Uncover New Technique to Exploit Azure Arc for Hybrid Escalation in Enterprise Environment and Maintain Persistence<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/researchers-uncover-new-technique-to-exploit-uncover-azure-arc\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers Uncover New Technique to Exploit Azure Arc for Hybrid Escalation in Enterprise Environment and Maintain Persistence Cybersecurity researchers have discovered a sophisticated attack technique that exploits Microsoft Azure Arc deployments to gain persistent access to enterprise environments. The research, conducted during recent red team operations, reveals how adversaries can leverage misconfigured Azure Arc installations [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5134","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5134"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5134"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5134\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5134"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5134"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5134"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}