Hackers use Windows RID hijacking to create hidden admin account
ID: 785accf3-22a1-51b9-ac41-050dbb999f5b
STIX ID: report--785accf3-22a1-51b9-ac41-050dbb999f5b
Feed Name: Bleeping Computer
AhnLab researchers report that the North Korean-linked Andariel group is using RID hijacking on Windows to convert hidden low-privilege local accounts into administrator accounts by modifying the SAM registry. The attack chain involves gaining SYSTEM access (via vulnerability exploitation and tools like PsExec and JuicyPotato), creating a hidden account, altering its RID with custom and open-source utilities, adding the account to Admin/RDP groups, and using registry export/restore techniques to hide tracks; mitigations include restricting privileged tool execution, protecting SAM access, monitoring LSA events, and enforcing MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
