RID Hijacking Technique Utilized by Andariel Attack Group
ID: 2d4125e4-e467-5625-a6e1-417d4b6bd74b
STIX ID: report--2d4125e4-e467-5625-a6e1-417d4b6bd74b
Feed Name: ASEC
AhnLab ASEC describes Andariel's use of RID Hijacking to escalate privileges and persist: attackers obtain SYSTEM (e.g., via PsExec/JuicyPotato), create a hidden account (name ending with '$'), change the account's RID in HKEY_LOCAL_MACHINE\SAM to match an administrator, export and re-import registry keys to minimize visibility, and in some cases use regini to adjust SAM permissions; the report includes behavioral commands, a comparison between a malicious sample and an open-source tool, and an MD5 hash for the sample.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
