{"id":6319,"date":"2025-08-21T10:04:13","date_gmt":"2025-08-21T10:04:13","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/21\/new-mitm6-ntlm-relay-attack-let-attackers-escalate-privileges-and-compromise-entire-domain\/"},"modified":"2025-08-21T10:04:13","modified_gmt":"2025-08-21T10:04:13","slug":"new-mitm6-ntlm-relay-attack-let-attackers-escalate-privileges-and-compromise-entire-domain","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/21\/new-mitm6-ntlm-relay-attack-let-attackers-escalate-privileges-and-compromise-entire-domain\/","title":{"rendered":"New MITM6 + NTLM Relay Attack Let Attackers Escalate Privileges and Compromise Entire Domain"},"content":{"rendered":"<p>    New MITM6 + NTLM Relay Attack Let Attackers Escalate Privileges and Compromise Entire Domain<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated attack chain that combines MITM6 with NTLM relay techniques to achieve full <a href=\"https:\/\/cybersecuritynews.com\/active-directory-checklist\/\" target=\"_blank\" rel=\"noreferrer noopener\">Active Directory<\/a> domain compromise.\u00a0<\/p>\n<p>The attack exploits Windows\u2019 default IPv6 auto-configuration behavior, allowing attackers to escalate from network access to Domain Admin privileges in minutes.\u00a0<\/p>\n<pre class=\"wp-block-preformatted\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Key Takeaways<\/mark><\/strong><br>1. Abuses Windows IPv6 auto-config and AD's 10-machine account quota for domain compromise.<br>2. Uses mitm6 + ntlmrelayx to create malicious accounts with RBCD to reach Domain Admin quickly.<br>3. Fix: Disable IPv6, set ms-DS-MachineAccountQuota = 0, enable signing, deploy DHCPv6 Guard.<\/pre>\n<p>This technique poses significant risks to organizations running standard Windows environments, as it leverages built-in protocols rather than requiring malware or zero-day exploits.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-ipv6-auto-configuration-attack\"><strong>IPv6 Auto-Configuration Attack<\/strong><\/h2>\n<p>Resecurity reports that the MITM6 attack targets a fundamental Windows behavior: automatic <a href=\"https:\/\/cybersecuritynews.com\/ipv6-security-guidance\/\" target=\"_blank\" rel=\"noreferrer noopener\">DHCPv6<\/a> requests sent when systems boot or connect to networks.\u00a0<\/p>\n<p>Even in organizations not actively using<a href=\"https:\/\/cybersecuritynews.com\/ipv6-security-best-practices-recommended-security-measures\/\" target=\"_blank\" rel=\"noreferrer noopener\"> IPv6<\/a>, Windows machines prioritize IPv6 configuration over IPv4, creating an exploitable attack surface.<\/p>\n<p>Attackers deploy the mitm6 tool to act as a rogue DHCPv6 server, responding to these requests and assigning malicious DNS server addresses to victim machines.\u00a0<\/p>\n<p>The command sudo mitm6 -d target.local \u2013no-ra establishes the attacker as the authoritative DNS server for the target domain.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfBbH3JmPR2u0jNr0PWgrR9gla_ks6PaWd83OsEI3fqnCWio0w6Sdmw-T7fp_ocRi2io6n-VDr_gIv3Murohl4fmap0rDsxTn7dOU4DCuwWv4U-13jcAryErWF9Y3Q7XXuKEz4beQ?key=TWIK_XpXhzPRKse1sIm6CA\" alt=\"Attack chain\"><figcaption class=\"wp-element-caption\">Attack chain<\/figcaption><\/figure>\n<\/div>\n<p>The attack chain continues with ntlmrelayx from the Impacket toolkit, which intercepts NTLM authentication attempts through WPAD (Web Proxy Auto-Discovery Protocol) spoofing.\u00a0<\/p>\n<p>The tool executes: sudo impacket-ntlmrelayx -ts -6 -t ldaps:\/\/target.local -wh fakewpad \u2013add-computer \u2013delegate-access, creating malicious computer accounts and configuring Resource-Based Constrained Delegation (RBCD).<\/p>\n<p>Active Directory\u2019s default ms-DS-MachineAccountQuota setting allows any authenticated user to add up to 10 machine accounts, enabling attackers to create controlled computer objects, reads the <a href=\"https:\/\/www.resecurity.com\/blog\/article\/mitm6-ntlm-relay-how-ipv6-auto-configuration-leads-to-full-domain-compromise\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">report<\/a>.<\/p>\n<p>These accounts can then modify their msDS-AllowedToActOnBehalfOfOtherIdentity attribute, allowing impersonation of privileged accounts, including Domain Administrators.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-recommendations\"><strong>Recommendations<\/strong><\/h2>\n<p>The attack\u2019s impact extends far beyond initial network compromise. Once successful, attackers can extract NTLM hashes using secretsdump.py \u201ctarget.local\/User:Password@target.local\u201d and conduct lateral movement with tools like CrackMapExec: crackmapexec smb 10.0.0.1\/8 -u administrator -H 1f937b21e2e0ada0d3d3f7cf58c8aade \u2013share.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdJXiFcm6N7vqoQ1lKLYfoDhp4idNhTJzOA2DR7IakvoD1Q8MArHdXbQqG8xf9hYv7rHCRB4QNjZ7u9ppAn-yAambgywrTnfrzWT5nPhga1MZga2BJ3zARjnTeS8Ms850811KN9tw?key=TWIK_XpXhzPRKse1sIm6CA\" alt=\"Take Control of Compromised Machines\"><figcaption class=\"wp-element-caption\">Take Control of Compromised Machines<\/figcaption><\/figure>\n<\/div>\n<p>Organizations face severe consequences, including full domain compromise, credential theft, service disruption, and potential data exfiltration.\u00a0<\/p>\n<p>The attack\u2019s stealthy nature makes detection challenging, as it abuses legitimate Windows protocols.<\/p>\n<p>Critical mitigation strategies include disabling IPv6 when not required, setting ms-DS-MachineAccountQuota = 0 to prevent unauthorized computer account creation, and enforcing SMB and LDAP signing to prevent relay attacks.\u00a0<\/p>\n<p>Network-level defenses should implement DHCPv6 Guard on switches and routers to block unauthorized IPv6 advertisements.<\/p>\n<p>This attack demonstrates how default configurations can create significant security vulnerabilities, emphasizing the need for proactive hardening of Active Directory environments and continuous monitoring for rogue network services.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong><code>Safely detonate suspicious files to uncover threats, enrich your investigations, and cut incident response time.\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=li_csn&amp;utm_medium=post&amp;utm_campaign=safe_detonation&amp;utm_content=demo&amp;utm_term=180825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start with an\u00a0ANYRUN sandbox trial<\/a>\u00a0\u2192\u00a0<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-mitm6-ntlm-relay-attack\/\">New MITM6 + NTLM Relay Attack Let Attackers Escalate Privileges and Compromise Entire Domain<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-mitm6-ntlm-relay-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New MITM6 + NTLM Relay Attack Let Attackers Escalate Privileges and Compromise Entire Domain A sophisticated attack chain that combines MITM6 with NTLM relay techniques to achieve full Active Directory domain compromise.\u00a0 The attack exploits Windows\u2019 default IPv6 auto-configuration behavior, allowing attackers to escalate from network access to Domain Admin privileges in minutes.\u00a0 Key Takeaways1. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-6319","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6319"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6319"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6319\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}