logo

The (Near) Return of the King: Account Takeover Using the BadSuccessor Technique

ID: 1d993e1f-b65b-5316-960a-397ba64f9474

STIX ID: report--1d993e1f-b65b-5316-960a-397ba64f9474

Feed Name: SpecterOps Blog

Threat Score
78/100

Date Published: 2025-10-20

Date Updated: 2026-04-30

Author: Logan Goins

...
...

This blog analyzes how BadSuccessor-related dMSA abuse remains exploitable after Microsoft’s patch, documents updated tools (SharpSuccessor and a native BOF named BadTakeover) that weaponize the technique, and demonstrates account takeover that can yield domain administrator access when an attacker has CreateChild on an OU, write permissions to specific msDS attributes, and at least one Windows Server 2025 DC; it urges defenders to harden DACLs and manage identity attack paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.