logo

Azure Application Proxy C2

ID: 2591679a-41c6-50eb-a586-77ddf75cb92f

STIX ID: report--2591679a-41c6-50eb-a586-77ddf75cb92f

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

### Executive Summary This report provides a step-by-step technical walkthrough and proof-of-concept for abusing Azure AD Application Proxy (which leverages Azure Service Bus) to create an inbound, certificate-authenticated C2 tunnel into an environment. It covers creating OAuth tokens and a client certificate, generating a CSR, interacting with the registration endpoint, establishing Service Bus-based WebSocket signaling channels, retrieving request payloads, and returning responses—demonstrating a stealthy technique that could be used by red teams or threat actors to tunnel C2 traffic through commonly trusted cloud infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.