Wednesday, September 16, 2026

MITM6 + NTLM Relay Attack Enables Full Domain Compromise

Cybersecurity researchers are highlighting a dangerous attack technique that combines rogue IPv6 configuration with NTLM credential relay to achieve complete Active Directory domain compromise, exploiting default Windows configurations that most organizations leave unchanged.

Attack Leverages Default Windows IPv6 Behavior

The MITM6 + NTLM Relay attack exploits Windows systems’ automatic DHCPv6 requests, even in networks that don’t actively use IPv6. 

Security firm Resecurity recently detailed how attackers can position themselves as rogue IPv6 DHCP servers, intercepting network communications and redirecting DNS queries to malicious servers.

Attack Heirarchy
Attack Heirarchy

The technique becomes particularly devastating when combined with NTLM relay attacks using tools like ntlmrelayx from the Impacket framework.

By spoofing Web Proxy Auto-Discovery Protocol (WPAD) services and relaying authentication attempts, attackers can capture credentials and escalate privileges across enterprise networks.

The attack’s effectiveness stems from three critical Active Directory default configurations that organizations often overlook.

First, Windows machines prioritize DHCPv6 over DHCPv4 during network initialization, creating an immediate attack vector.

Taking Control of Compromised Machines

Second, any authenticated domain user can add up to ten machine accounts without special privileges through the ms-DS-MachineAccountQuota attribute.

Third, computer accounts can modify their own msDS-AllowedToActOnBehalfOfOtherIdentity attribute, enabling Resource-Based Constrained Delegation (RBCD) abuse.

These seemingly benign defaults create a perfect storm for privilege escalation. Once attackers control a machine account, they can configure RBCD to impersonate privileged accounts, including Domain Administrators, ultimately gaining complete control over the entire domain infrastructure.

The attack follows a systematic approach. Attackers first establish themselves as fake DHCPv6 servers using mitm6, then relay intercepted authentication attempts to LDAP services.

 This process automatically creates malicious computer accounts with impersonation capabilities.

Subsequently, tools like secretsdump.py extract password hashes from compromised systems, while CrackMapExec tests stolen credentials across entire network ranges to identify accessible hosts.

The final stage involves using extracted credentials with tools like WMIExec or PsExec to gain remote system control, enabling lateral movement and persistent access across the compromised network.

Security experts warn that successful MITM6 + NTLM Relay attacks result in catastrophic consequences. Beyond immediate domain compromise, organizations face credential theft, widespread lateral movement, and potential ransomware deployment.

The attack can disrupt essential services through DNS poisoning while providing attackers with persistent access even after initial entry points are discovered.

Cybersecurity professionals recommend immediate defensive measures, including disabling IPv6 if unused, implementing LDAP signing and channel binding, and restricting machine account creation privileges.

Organizations should also monitor for suspicious DHCP activities and implement network segmentation to limit lateral movement potential.

The attack’s reliance on default configurations underscores the critical importance of security hardening in enterprise environments.

Find this News Interesting! Follow us on Google NewsLinkedIn, and X to Get Instant Updates!

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Google Search Makes It Harder to See Where a Link Really Goes Before You Click

Google has begun routing some organic Search result links...

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

Phishing operators are increasingly shifting away from malware-laden attachments...

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Threat actors are actively exploiting a critical vulnerability in...

Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week

Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China...

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

Two critical unauthenticated vulnerability chains in the widely used...

Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories

A stored cross-site scripting (XSS) vulnerability in Telegram Desktop...

Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds

A threat actor exploited a critical pre-authentication remote code...

Related Articles

Recent News