logo

When Good Accounts Go Bad: Exploiting Delegated Managed Service Accounts in Active Directory

ID: 16bba2f6-1bef-5c38-94c7-9ee4515cf111

STIX ID: report--16bba2f6-1bef-5c38-94c7-9ee4515cf111

Feed Name: Palo Alto Networks Unit 42

Threat Score
78/100

Date Published: 2025-08-06

Date Updated: 2026-04-28

Author: Noam Sala, Paul Michaud II and Ofir Shlomo

...
...

This Unit 42 report analyzes 'BadSuccessor', a Windows Server 2025-specific privilege escalation technique that lets an attacker who can create or modify delegated Managed Service Accounts (dMSAs) impersonate superseded accounts — including domain administrators — by setting dMSA attributes to simulate a completed migration. The report documents PoC tools (SharpSuccessor, Pentest-Tools module), demonstrates follow-on abuse with tools like Rubeus, maps detection footprints to event IDs (4662, 5136, 5137, 2946) and provides XDR/Windows audit-based detection queries and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.