logo

Hackers use Windows RID hijacking to create hidden admin account

ID: 785accf3-22a1-51b9-ac41-050dbb999f5b

STIX ID: report--785accf3-22a1-51b9-ac41-050dbb999f5b

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-01-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

AhnLab researchers report that the North Korean-linked Andariel group is using RID hijacking on Windows to convert hidden low-privilege local accounts into administrator accounts by modifying the SAM registry. The attack chain involves gaining SYSTEM access (via vulnerability exploitation and tools like PsExec and JuicyPotato), creating a hidden account, altering its RID with custom and open-source utilities, adding the account to Admin/RDP groups, and using registry export/restore techniques to hide tracks; mitigations include restricting privileged tool execution, protecting SAM access, monitoring LSA events, and enforcing MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.