PRTremote: Extracting Entra ID Cookies via Scheduled Tasks
Score: 8/10

PRTremote: Extracting Entra ID Cookies via Scheduled Tasks

The Armadin Attacker uses a new tool called PRTremote to hijack Entra ID Primary Refresh Tokens by executing scheduled tasks within interactive user sessions over SMB.

Executive Summary

Armadin researchers have detailed a technique and tool named PRTremote that allows attackers with local administrator privileges to bypass the Windows logon session boundary and extract Primary Refresh Tokens (PRTs). By leveraging the TASK_LOGON_INTERACTIVE_TOKEN logon type in Windows Scheduled Tasks, an operator can execute commands within a target user's active session without needing their password, NT hash, or MFA factors.

The attack chain involves using the native Microsoft binary BrowserCore.exe to request PRT cookies (x-ms-RefreshTokenCredential) through local session redirection. These cookies can then be redeemed for Entra ID access tokens that inherit the original user's Multi-Factor Authentication (MFA) and device compliance claims. This method is particularly dangerous because it avoids traditional detection triggers like process injection or token theft, relying instead on signed Microsoft binaries and legitimate task scheduling mechanisms.

This technique highlights a critical risk for organizations using Entra ID (formerly Azure AD) for Single Sign-On (SSO). It demonstrates that local administrative access on a workstation can be rapidly escalated to full cloud environment access, bypassing Conditional Access policies that rely on MFA or compliant devices. Security teams should prioritize monitoring for anomalous remote scheduled task registrations and hardening privileged access workstations.

Key Details

Threat Name

PRTremote

Affects

Microsoft SSO browser extension

Adversary

Armadin Attacker

Malware/Tools

PRTremote, AADInternals, mimikatz, roadtools, Impacket

Report Score

8out of 10
Quality Score
Good
IOC Quality4
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure10
Technical Depth9

Sources