Ghost SPN Attack Lets Hackers Conduct Stealthy Kerberoasting Under the Radar
ID: d78cabfa-cce5-501e-b149-61235f8ab1f2
STIX ID: report--d78cabfa-cce5-501e-b149-61235f8ab1f2
Feed Name: cybersecurityNews.com
A Trellix analysis describes the “Ghost SPN” attack — a Kerberoasting evolution where adversaries abuse delegated Active Directory permissions (e.g., GenericAll or WriteSPN) to temporarily assign service principal names to normal user accounts, obtain TGS tickets encrypted with RC4-HMAC-MD5, extract and crack them offline, then immediately remove the SPN to eliminate forensic evidence. The report outlines a three-phase lifecycle (SPN assignment, extraction/offline cracking, cleanup), explains how the technique defeats traditional detection models, and recommends mitigations including ACL auditing, granular msDS-ServicePrincipalName change logging, enforcing AES-only Kerberos, password resets for exposed accounts, and deploying behavioral NDR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
