logo

RID Hijacking Technique Utilized by Andariel Attack Group

ID: 2d4125e4-e467-5625-a6e1-417d4b6bd74b

STIX ID: report--2d4125e4-e467-5625-a6e1-417d4b6bd74b

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-01-22

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC describes Andariel's use of RID Hijacking to escalate privileges and persist: attackers obtain SYSTEM (e.g., via PsExec/JuicyPotato), create a hidden account (name ending with '$'), change the account's RID in HKEY_LOCAL_MACHINE\SAM to match an administrator, export and re-import registry keys to minimize visibility, and in some cases use regini to adjust SAM permissions; the report includes behavioral commands, a comparison between a malicious sample and an open-source tool, and an MD5 hash for the sample.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.