Uploaded December 2025 | Updated September 2026, 2 weeks ago
Presentation Slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/ee/Alon%20Dankner%20-%20Your%20RPA%20is%20Mine%20-%20OWASP%20DC%202025.pdf
Our research uncovers a new threat vector for enterprises in the realm of Robotic Process Automation (RPA), challenging the assumption that RPA automations are inherently secure. We demonstrate the first-ever RPA malware capable of infecting automations built in UiPath—a leading RPA development platform—while evading traditional security measures. By compromising automation environments, this attack triggers a devastating domino effect across an entire enterprise.
Across industries and departments, RPA adoption skyrockets in enterprises pursuing digital transformation. RPA development platforms like UiPath, Microsoft Power Automate, and ServiceNow enable non-technical business users to create and deploy powerful automations by composing drag-and-drop components (e.g., sending email and executing SQL query). These automations handle and manipulate critical enterprise data.
We demonstrate an innovative malware that allows attackers to infect all UiPath automations and establish persistence. By stealing keys and tokens from the automation’s runtime environment, our malware infects UiPath automations and rapidly spreads to all available feeds. As a result, the malicious payload runs on every connected runtime environment, compromising any desktop and cloud.
This malware's unique ability to perform only UiPath actions allows it to evade traditional security measures. Our malware can gain initial access to the enterprise, either by a malicious actor leveraging the UiPath public marketplace or by the automation developer overlooking implementation vulnerabilities such as command injection.
Our findings demonstrate a novel malware propagation avenue that bypasses traditional defences; a route that proves effective for deploying any malware, including ransomware. The dangerous misconception that RPA is secure by design has persisted for years, lulling security teams and leaving organizations vulnerable to emerging threats. To address these critical issues, we provide essential, actionable mitigations to secure RPA automations and protect against this evolving internal and external attack surface.
Alon Dankner
Nokod Security
Security Researcher
Alon Dankner is a security researcher at Nokod Security, a low-code/no-code cybersecurity startup. He holds a B.Sc. in Computer Science from the University of Haifa (cum laude) and an M.Sc. from the Technion (cum laude). Computers and network security have always been a topic of interest to him, and his research focuses on the security of low-code/no-code systems and industrial control systems.
alon@nokodsecurity.com
linkedin.com/in/alon-dankner
Managed by the OWASP® Foundation
owasp.org
Presentation Slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/ee/Alon%20Dankner%20-%20Your%20RPA%20is%20Mine%20-%20OWASP%20DC%202025.pdf
Our research uncovers a new threat vector for enterprises in the realm of Robotic Process Automation (RPA), challenging the assumption that RPA automations are inherently secure. We demonstrate the first-ever RPA malware capable of infecting automations built in UiPath—a leading RPA development platform—while evading traditional security measures. By compromising automation environments, this attack triggers a devastating domino effect across an entire enterprise.
Across industries and departments, RPA adoption skyrockets in enterprises pursuing digital transformation. RPA development platforms like UiPath, Microsoft Power Automate, and ServiceNow enable non-technical business users to create and deploy powerful automations by composing drag-and-drop components (e.g., sending email and executing SQL query). These automations handle and manipulate critical enterprise data.
We demonstrate an innovative malware that allows attackers to infect all UiPath automations and establish persistence. By stealing keys and tokens from the automation’s runtime environment, our malware infects UiPath automations and rapidly spreads to all available feeds. As a result, the malicious payload runs on every connected runtime environment, compromising any desktop and cloud.
This malware's unique ability to perform only UiPath actions allows it to evade traditional security measures. Our malware can gain initial access to the enterprise, either by a malicious actor leveraging the UiPath public marketplace or by the automation developer overlooking implementation vulnerabilities such as command injection.
Our findings demonstrate a novel malware propagation avenue that bypasses traditional defences; a route that proves effective for deploying any malware, including ransomware. The dangerous misconception that RPA is secure by design has persisted for years, lulling security teams and leaving organizations vulnerable to emerging threats. To address these critical issues, we provide essential, actionable mitigations to secure RPA automations and protect against this evolving internal and external attack surface.
Alon Dankner
Nokod Security
Security Researcher
Alon Dankner is a security researcher at Nokod Security, a low-code/no-code cybersecurity startup. He holds a B.Sc. in Computer Science from the University of Haifa (cum laude) and an M.Sc. from the Technion (cum laude). Computers and network security have always been a topic of interest to him, and his research focuses on the security of low-code/no-code systems and industrial control systems.
alon@nokodsecurity.com
linkedin.com/in/alon-dankner
Managed by the OWASP® Foundation
owasp.org










