When Good Accounts Go Bad: Exploiting Delegated Managed Service Accounts in Active Directory
ID: 16bba2f6-1bef-5c38-94c7-9ee4515cf111
STIX ID: report--16bba2f6-1bef-5c38-94c7-9ee4515cf111
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-08-06
Date Updated: 2026-04-28
Author: Noam Sala, Paul Michaud II and Ofir Shlomo
This Unit 42 report analyzes 'BadSuccessor', a Windows Server 2025-specific privilege escalation technique that lets an attacker who can create or modify delegated Managed Service Accounts (dMSAs) impersonate superseded accounts — including domain administrators — by setting dMSA attributes to simulate a completed migration. The report documents PoC tools (SharpSuccessor, Pentest-Tools module), demonstrates follow-on abuse with tools like Rubeus, maps detection footprints to event IDs (4662, 5136, 5137, 2946) and provides XDR/Windows audit-based detection queries and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
