logo

Ghost SPN Attack Lets Hackers Conduct Stealthy Kerberoasting Under the Radar

ID: d78cabfa-cce5-501e-b149-61235f8ab1f2

STIX ID: report--d78cabfa-cce5-501e-b149-61235f8ab1f2

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-26

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A Trellix analysis describes the “Ghost SPN” attack — a Kerberoasting evolution where adversaries abuse delegated Active Directory permissions (e.g., GenericAll or WriteSPN) to temporarily assign service principal names to normal user accounts, obtain TGS tickets encrypted with RC4-HMAC-MD5, extract and crack them offline, then immediately remove the SPN to eliminate forensic evidence. The report outlines a three-phase lifecycle (SPN assignment, extraction/offline cracking, cleanup), explains how the technique defeats traditional detection models, and recommends mitigations including ACL auditing, granular msDS-ServicePrincipalName change logging, enforcing AES-only Kerberos, password resets for exposed accounts, and deploying behavioral NDR.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.